Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 20 Aug 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | baserCMS before 5.3.0 contains a SQL injection vulnerability in BcDatabaseService.php that allows authenticated administrators to inject attacker-controlled table names and configuration values directly into SQL statements across sequence update, CSV export, and table management operations. Attackers can chain a backup restore code injection flaw, where PHP code outside class definitions in schema files executes unconditionally upon loading, to plant malicious table names and trigger error-based SQL injection that retrieves database version, schema contents, and arbitrary data from the PostgreSQL backend. | |
| Title | baserCMS < 5.3.0 SQL Injection and Code Injection via BcDatabaseService.php | |
| Weaknesses | CWE-89 CWE-94 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-20T13:58:05.913Z
Reserved: 2026-08-19T14:53:58.574Z
Link: CVE-2026-76635
No data.
Status : Received
Published: 2026-08-20T14:17:59.973
Modified: 2026-08-20T14:17:59.973
Link: CVE-2026-76635
No data.
OpenCVE Enrichment
No data.