SQL injection in baserCMS - #VU140522

 

SQL injection in baserCMS - #VU140522

Published: July 30, 2026


Vulnerability identifier: #VU140522
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-89
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to SQL injection in BcDatabaseService.php when processing database backup and restore operations. A remote user can inject crafted SQL identifiers and database input to disclose sensitive information.

Exploitation requires valid login access and was demonstrated through the backup download and restore workflow.


Affected software

baserCMS

Remediation

Install security update from vendor's website.

baserCMS - update to 5.3.0

External References

Related Security Bulletins