Retour à la veille

CVE-2026-97150

Publié : 30 septembre 2026
Modifié : 30 septembre 2026
Lien officiel NVD
Score CVSS
7.2
HIGH

Description détaillée

When converting baserCMS4-style addons to baserCMS5-style ones, BcAddonMigrator includes "config.php" from the addon, which means the PHP code in the file is executed. Arbitrary files on the system may be read or deleted by an administrative user.

Vecteur d'attaque (CVSS)

Vecteur brut :CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Références et Patchs