CVE-2018-18942: Basercms
High severity, CVSS 7.2. EPSS: 2.4% chance of exploitation in the next 30 days.
In baserCMS before 4.1.4, lib\Baser\Model\ThemeConfig.php allows remote attackers to execute arbitrary PHP code via the admin/theme_configs/form data[ThemeConfig][logo] parameter.
Affected products
- Basercms Basercms: before 4.1.4 (fixed in 4.1.4)
Published 2018-11-05. Last modified 2026-06-17.