Cross-site scripting in baserCMS - CVE-2020-15276
Published: October 29, 2020 / Updated: April 27, 2026
baserCMS
baserproject
Description
The vulnerability allows a remote attacker to execute arbitrary script code in the victim's browser.
The vulnerability exists due to cross-site scripting in blog comment posting when handling user-supplied comment content. A remote attacker can submit a specially crafted comment to execute arbitrary script code in the victim's browser.