Description
When converting baserCMS4-style addons to baserCMS5-style ones,
BcAddonMigrator includes "config.php" from the addon, which means the PHP code in the file is executed.
Arbitrary files on the system may be read or deleted by an administrative user.
Published: 2026-09-30
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary file read/write
Action: Patch Immediately
AI Analysis

Impact

During conversion of baserCMS4-style addons to baserCMS5-style ones, the migration tool automatically includes "config.php" from the addon, causing the PHP code in that file to be executed. An attacker can supply a malicious config.php, allowing execution of arbitrary PHP code under an administrative user’s privileges, leading to arbitrary file read or delete on the system. The weakness aligns with CWE‑829: Improper Restriction of Operations within the Bounds of a Memory Buffer, exposing the application to severe confidentiality and integrity compromise.

Affected Systems

The vulnerability affects the BcAddonMigrator component of baserCMS Users Community. No specific versions are listed as impacted, and the risk applies to any instance where administrators run the migration tool on untrusted addon packages.

Risk and Exploitability

The assigned CVSS score of 8.6 reflects high severity. While no EPSS score is publicly available, the lack of an EPSS value and absence from the CISA KEV catalog suggests the exploitation probability is not currently confirmed, but the high CVSS indicates significant potential impact if an administrator is compromised or supplied with a malicious addon. The likely attack vector involves an administrative user executing the migration tool on an attacker‑crafted addon, which then causes arbitrary PHP code execution during a routine task.

Generated by OpenCVE AI on September 30, 2026 at 12:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the patch found in commit e836bc8, which disables automatic inclusion of config.php during migration
  • Limit the migration tool to use only trusted, reviewed addons and avoid deploying unverified packages
  • Enforce least privilege for the migration process, using stringent file permission checks or a confined runtime to prevent arbitrary file access

Generated by OpenCVE AI on September 30, 2026 at 12:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Title Arbitrary PHP Code Execution via Config.php Inclusion during Addon Migration

Wed, 30 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Description When converting baserCMS4-style addons to baserCMS5-style ones, BcAddonMigrator includes "config.php" from the addon, which means the PHP code in the file is executed. Arbitrary files on the system may be read or deleted by an administrative user.
Weaknesses CWE-829
References
Metrics cvssV3_0

{'score': 7.2, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-09-30T14:38:59.606Z

Reserved: 2026-09-24T02:49:08.352Z

Link: CVE-2026-97150

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-30T08:16:36.230

Modified: 2026-09-30T08:16:36.230

Link: CVE-2026-97150

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T13:00:16Z

Weaknesses
  • CWE-829

    Inclusion of Functionality from Untrusted Control Sphere