Impact
During conversion of baserCMS4-style addons to baserCMS5-style ones, the migration tool automatically includes "config.php" from the addon, causing the PHP code in that file to be executed. An attacker can supply a malicious config.php, allowing execution of arbitrary PHP code under an administrative user’s privileges, leading to arbitrary file read or delete on the system. The weakness aligns with CWE‑829: Improper Restriction of Operations within the Bounds of a Memory Buffer, exposing the application to severe confidentiality and integrity compromise.
Affected Systems
The vulnerability affects the BcAddonMigrator component of baserCMS Users Community. No specific versions are listed as impacted, and the risk applies to any instance where administrators run the migration tool on untrusted addon packages.
Risk and Exploitability
The assigned CVSS score of 8.6 reflects high severity. While no EPSS score is publicly available, the lack of an EPSS value and absence from the CISA KEV catalog suggests the exploitation probability is not currently confirmed, but the high CVSS indicates significant potential impact if an administrator is compromised or supplied with a malicious addon. The likely attack vector involves an administrative user executing the migration tool on an attacker‑crafted addon, which then causes arbitrary PHP code execution during a routine task.
OpenCVE Enrichment