CVE-2017-10843: Basercms

High severity, CVSS 7.5. EPSS: 1.4% chance of exploitation in the next 30 days.

baserCMS version 3.0.14 and earlier, 4.0.5 and earlier allows remote attackers to delete arbitrary files via unspecified vectors when the "File" field is being used in the mail form.

Affected products

  • Basercms Basercms: from 3.0.0, up to and including 3.0.14; from 4.0.0, up to and including 4.0.5

Published 2017-08-29. Last modified 2026-06-17.