CVE-2012-1248: Basercms

Medium severity, CVSS 5.1. EPSS: 2.7% chance of exploitation in the next 30 days.

app/config/core.php in baserCMS 1.6.15 and earlier does not properly handle installations in shared-hosting environments, which allows remote attackers to hijack sessions by leveraging administrative access to a different domain.

Affected products

  • Basercms Basercms: up to and including 1.6.15; version 1.5.4 only; version 1.5.5 only; version 1.5.6 only; version 1.5.7 only; version 1.5.8 only; …

Published 2012-05-15. Last modified 2026-06-16.