CVE-2026-97150
7.2
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Summary
When converting baserCMS4-style addons to baserCMS5-style ones, BcAddonMigrator includes "config.php" from the addon, which means the PHP code in the file is executed. Arbitrary files on the system may be read or deleted by an administrative user.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| baserCMS Users Community | BcAddonMigrator | 0 <= 5.2.0 | affected |
Weaknesses
- CWE-829: Inclusion of functionality from untrusted control sphere
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: total
References
- https://jvn.jp/en/jp/JVN21754394
- https://basercms.net/security/JVN_21754394
- https://github.com/baserproject/BcAddonMigrator/commit/e836bc875e26910e1b5862f96cf280b4f064c104
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.