CVE detail
CVE-2020-15155 — CVE-2020-15155
Published 2020-08-28 · Modified 2026-06-17 · Vendor basercms · Product basercms · Source nvd
HIGH
severity
CVSS-derived band
0.0129
EPSS probability
exploitation probability, 30d
67.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
baserCMS 4.3.6 and earlier is affected by Cross Site Scripting (XSS) via arbitrary script execution. Admin access is required to exploit this vulnerability. The affected components is toolbar.php. The issue is fixed in version 4.3.7.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References