Cross-site scripting in baserCMS - CVE-2020-15273
Published: October 29, 2020 / Updated: April 27, 2026
baserCMS
baserproject
Description
The vulnerability allows a remote user to execute arbitrary script code.
The vulnerability exists due to cross-site scripting in edit feed settings, edit widget area, sub site new registration, and new category registration when handling crafted input. A remote user can submit specially crafted input to execute arbitrary script code.
Exploitation requires an administrator to be logged in.