Impact
The vulnerability is a stored cross‑site scripting flaw located in the custom content description feature of baserCMS. A malicious actor can inject arbitrary JavaScript that is persisted and rendered when users view the affected content. Execution of that script occurs within the victim's browser, allowing the attacker to perform client‑side attacks such as session hijacking, credential theft, or defacement. This flaw represents a typical reflected input injection weakness (CWE‑79) that can break the integrity and confidentiality of the application.
Affected Systems
The flaw exists in all baserCMS installations that expose the custom content description field for user input. No specific version constraints are listed; therefore any deployment using the default content description mechanism could be vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 5.1 places the issue in the moderate severity range. The EPSS score is not available, and the vulnerability is not currently enumerated in the CISA KEV catalog, indicating no confirmed widespread exploitation. Likely attack requires authenticated access to the CMS’s content editing interface or a compromised user account to inject the malicious payload, after which any user who loads the stored content will be affected. The overall risk is considered moderate pending the discovery of a patch or mitigation.
OpenCVE Enrichment