CVE-2023-25655 is a critical arbitrary file upload vulnerability affecting baserCMS versions prior to 4.7.5, allowing unauthenticated attackers to upload any file to the system. With a CVSS score of 9.8, this vulnerability poses a severe risk, enabling full compromise of confidentiality, integrity, and availability. While no public exploits, KEV entries, or significant community discussion are currently observed, the ease of exploitation (AV:N/AC:L/PR:N/UI:N) makes it a high-priority patch. Organizations using affected baserCMS versions should upgrade to 4.7.5 immediately to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.7.5CPE matchmatch criteria | cpe:2.3:a:basercms:basercms:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.