-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| baserproject/basercms | composer | < 5.0.9 | 5.0.9 |
The patch adds 'escape' => true to the figcaption element in BcAdminFormHelper's control method. This indicates user input rendered in form controls (likely used during installation) was not properly escaped. Since the vulnerability manifests in the Installer feature, unescaped form values could flow into OS command execution contexts. The direct correlation between the patch location and the CWE-78 vulnerability type confirms this was the injection vector.
Ongoing coverage of React2Shell