SQL injection in baserCMS - #VU152771

 

SQL injection in baserCMS - #VU152771

Published: September 29, 2026


Vulnerability identifier: #VU152771
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-89
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to improper neutralization of special elements in an SQL command in public Custom Content front actions when handling nested contain query parameters. A remote attacker can send a crafted query parameter to execute arbitrary code.

The application-level code-execution chain requires MySQL or MariaDB.


Affected software

baserCMS

Remediation

Install security update from vendor's website.

baserCMS - addressed in versions 5.3.1, 5.4.1

External References

Related Security Bulletins