Impact
The vulnerability is a missing authentication check for a critical functionality within baserCMS. A remote attacker who can reach the application without valid credentials can potentially retrieve sensitive information. This flaw aligns with the Authentication Bypass weakness (CWE‑306).
Affected Systems
baserCMS, as distributed by the baserCMS User Community. The affected versions are not specified in the advisory, so all installations of baserCMS should be considered at risk until an updated version is available.
Risk and Exploitability
The CVSS score for this issue is 6.9, reflecting moderate severity. The EPSS score is not available, but the vulnerability is not listed in the CISA KEV catalog. The path of exploitation is inferred to be remote via the web interface, with no authentication required to invoke the function. Because no authentication controls are enforced, an unauthenticated user can exploit this flaw if the vulnerable route is reachable.
OpenCVE Enrichment