Cross-site scripting in baserCMS - CVE-2020-15277
Published: October 29, 2020 / Updated: April 27, 2026
baserCMS
baserproject
Description
The vulnerability allows a remote user to execute arbitrary script code.
The vulnerability exists due to improper neutralization of input during web page generation in the edit template feature when editing templates. A remote user can inject a specially crafted script into a template to execute arbitrary script code.
Exploitation requires an administrator to be logged in.