Published:2026/07/31  Last Updated:2026/07/31

JVNVU#94952030
CSV file injection vulnerability in BaserCMS

Overview

BaserCMS provided by baserCMS Users Community contains a CSV file injection vulnerability.

Products Affected

  • BaserCMS versions prior to 5.3.0

Description

BaserCMS provided by baserCMS Users Community contains the following vulnerability.

  • Improper neutralization of formula elements in a CSV file (CWE-1236)
    • CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:L Base Score 5.1
    • CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L Base Score 7.1
    • CVE-2026-65875

Impact

If a user downloads and opens a CSV file containing malicious code injected by an attacker, the malicious code may be executed.

Solution

Update the Software
Update the software to the latest version according to the information provided by the developer.

Vendor Status

Vendor Status Last Update Vendor Notes
baserCMS Users Community Vulnerable 2026/07/31 baserCMS Users Community website

References

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

Credit

This vulnerability was reported by the following persons to JPCERT/CC. JPCERT/CC coordinated with the developer.

VCSLab - Viettel Cyber Security quanlna2 (Le Nguyen Anh Quan)
VCSLab - Viettel Cyber Security namdi (Do Ich Nam)
VCSLab - Viettel Cyber Security minhnn42 (Nguyen Ngoc Minh)

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE CVE-2026-65875
JVN iPedia