← Voltar à pesquisa de CVEs

CVE-2026-30878

baserCMS

Descrição

baserCMS is a website development framework. Prior to version 5.2.3, a public mail submission API allows unauthenticated users to submit mail form entries even when the corresponding form is not accepting submissions. This bypasses administrative controls intended to stop form intake and enables spam or abuse via the API. This issue has been patched in version 5.2.3.

CVSS 5.3EPSS 0.382%Risco 0.55
Ver fonte
Publicação
2026-03-31 01:16:35
Versões afetadas
<5.2.3
Tipo
Core software
Vetor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N