SQL injection in baserCMS - #VU152766

 

SQL injection in baserCMS - #VU152766

Published: September 29, 2026


Vulnerability identifier: #VU152766
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-89
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to improper neutralization of special elements used in an SQL command in the public BlogTags API when processing nested contain parameters that enable an associated BlogPosts query. A remote attacker can send a crafted request containing raw SQL conditions to execute arbitrary code.

The SQL injection read primitives apply to MySQL, MariaDB, PostgreSQL, and SQLite; stacked statements and the administrator-account creation chain to code execution are specific to MySQL and MariaDB.


Affected software

baserCMS

Remediation

Install security update from vendor's website.

baserCMS - addressed in versions 5.3.1, 5.4.1

External References

Related Security Bulletins