Impact
The vulnerability is a moderate‑severity cross‑site scripting flaw caused by a script validation bypass in baserCMS. An attacker can inject arbitrary JavaScript that will run in a victim’s browser when the content is displayed, enabling session hijacking, data theft, or defacement. The weakness is categorized as CWE‑79.
Affected Systems
The flaw impacts the baserCMS web application; no specific product version is listed, so any deploying instance that has not applied a vendor patch may be susceptible.
Risk and Exploitability
The CVSS score of 5.1 indicates a moderate risk. The EPSS score is unavailable and the vulnerability is not listed in the CISA KEV catalog, implying a lower likelihood of exploitation at present. The attack vector is remote, relying on the attacker’s ability to submit or modify content that bypasses the script validation check, thereby executing malicious code in users’ browsers.
OpenCVE Enrichment