SQL injection in baserCMS - #VU140522
Published: July 30, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to SQL injection in BcDatabaseService.php when processing database backup and restore operations. A remote user can inject crafted SQL identifiers and database input to disclose sensitive information.
Exploitation requires valid login access and was demonstrated through the backup download and restore workflow.