SQL injection in baserCMS - #VU152772
Published: September 29, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to SQL injection in the BlogPostsService eager-load query handling when processing crafted nested contain query parameters on public blog front routes. A remote attacker can send a specially crafted request to execute arbitrary code.
Stacked data-modification statements and the administrator-creation-to-plugin execution chain are specific to MySQL and MariaDB deployments.