CVE-2026-30940 Details
Description
baserCMS is a website development framework. Prior to version 5.2.3, a path traversal vulnerability exists in the theme file management API (/baser/api/admin/bc-theme-file/theme_files/add.json) that allows arbitrary file write. An authenticated administrator can include ../ sequences in the path parameter to create a PHP file in an arbitrary directory outside the theme directory, which may result in remote code execution (RCE). This issue has been patched in version 5.2.3.
A path traversal vulnerability has been identified in baserCMS versions prior to 5.2.3, specifically within the theme file management API. This vulnerability allows authenticated administrators to write arbitrary files by exploiting the path parameter with '../' sequences. The issue can lead to remote code execution by creating a PHP file in a directory outside the theme folder. The vulnerability arises because the path parameter is not properly sanitized, enabling unauthorized file creation.
Users are advised to update baserCMS to version 5.2.3 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 2, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://basercms.net/security/JVN_20837860 | [email protected] | Vendor Advisory |
| https://github.com/baserproject/basercms/releases/tag/5.2.3 | [email protected] | Release Notes |
| https://github.com/baserproject/basercms/security/advisories/GHSA-c5c6-37vq-pjcq | [email protected] | ExploitVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
| CWE-73 | External Control of File Name or Path | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| basercms basercms | < 5.2.3 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 1, 2026 | Initial Analysis | [email protected] |
| Mar 31, 2026 | New CVE Received | [email protected] |