Published:2026/07/31 Last Updated:2026/07/31
JVNVU#94952030
CSV file injection vulnerability in BaserCMS
Overview
BaserCMS provided by baserCMS Users Community contains a CSV file injection vulnerability.
Products Affected
- BaserCMS versions prior to 5.3.0
Description
BaserCMS provided by baserCMS Users Community contains the following vulnerability.
- Improper neutralization of formula elements in a CSV file (CWE-1236)
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:L Base Score 5.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L Base Score 7.1
- CVE-2026-65875
Impact
If a user downloads and opens a CSV file containing malicious code injected by an attacker, the malicious code may be executed.
Solution
Update the Software
Update the software to the latest version according to the information provided by the developer.
Vendor Status
| Vendor | Status | Last Update | Vendor Notes |
|---|---|---|---|
| baserCMS Users Community | Vulnerable | 2026/07/31 | baserCMS Users Community website |
References
JPCERT/CC Addendum
Vulnerability Analysis by JPCERT/CC
Credit
This vulnerability was reported by the following persons to JPCERT/CC. JPCERT/CC coordinated with the developer.
VCSLab - Viettel Cyber Security quanlna2 (Le Nguyen Anh Quan)
VCSLab - Viettel Cyber Security namdi (Do Ich Nam)
VCSLab - Viettel Cyber Security minhnn42 (Nguyen Ngoc Minh)
Other Information
| JPCERT Alert |
|
| JPCERT Reports |
|
| CERT Advisory |
|
| CPNI Advisory |
|
| TRnotes |
|
| CVE |
CVE-2026-65875 |
| JVN iPedia |
|