OS Command Injection in baserCMS - CVE-2026-30877
Published: April 27, 2026
baserCMS
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary OS commands.
The vulnerability exists due to improper neutralization of special elements used in an OS command in the update functionality when handling update operations. A remote privileged user can send crafted input to execute arbitrary OS commands.
Commands are executed with the privileges of the user account running baserCMS.