{"id":"GHSA-6wr6-54mw-mvhr","summary":"BaserCMS privilege escallation","details":"BaserCMS before 1.6.12 does not properly restrict additions to the membership of the operators group, which allows remote authenticated users to gain privileges via unspecified vectors.","aliases":["CVE-2011-2674"],"modified":"2026-09-10T03:49:31.447734027Z","published":"2022-05-13T01:08:49Z","database_specific":{"nvd_published_at":"2011-10-02T02:53:00Z","cwe_ids":["CWE-269"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2024-01-15T18:23:42Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2011-2674"},{"type":"PACKAGE","url":"https://github.com/baserproject/basercms"},{"type":"WEB","url":"http://basercms.net/patch/JVN09789751"},{"type":"WEB","url":"http://jvn.jp/en/jp/JVN16617002/index.html"},{"type":"WEB","url":"http://jvndb.jvn.jp/jvndb/JVNDB-2011-000066"}],"affected":[{"package":{"name":"baserproject/basercms","ecosystem":"Packagist","purl":"pkg:composer/baserproject/basercms"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.6.12"}]}],"versions":["0.0.1","0.0.2","0.0.3","0.0.4","0.0.5","0.0.6","0.0.7","0.0.8","1.0.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-6wr6-54mw-mvhr/GHSA-6wr6-54mw-mvhr.json"}}],"schema_version":"1.9.0"}