SQL injection in baserCMS - #VU152771
Published: September 29, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to improper neutralization of special elements in an SQL command in public Custom Content front actions when handling nested contain query parameters. A remote attacker can send a crafted query parameter to execute arbitrary code.
The application-level code-execution chain requires MySQL or MariaDB.