CVE-2021-41243 describes a potential Zip Slip and OS Command Injection vulnerability in the management system of baserCMS. Authenticated users with file upload privileges can exploit this by uploading specially crafted zip files, leading to arbitrary command execution on the host operating system. This vulnerability carries a high CVSS score of 8.8, indicating a critical risk due to its network-based attack vector, low complexity, and high impact on confidentiality, integrity, and availability. While no active exploitation has been observed, nor are there public exploits available in Metasploit or ExploitDB, the lack of community discussion and media coverage suggests low public awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.5.4CPE matchmatch criteria | cpe:2.3:a:basercms:basercms:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.