basercms-install: baserCMS Installation - Exposure

日期: 2025-08-01 | 影响软件: baserCMS | POC: 已公开

漏洞描述

baserCMS installation panel was detected. This indicates an incomplete installation that could be exploited by unauthorized users to set up the CMS with attacker-controlled parameters.

PoC代码[已公开]

id: basercms-install

info:
  name: baserCMS Installation - Exposure
  author: ritikchaddha
  severity: critical
  description: |
    baserCMS installation panel was detected. This indicates an incomplete installation that could be exploited by unauthorized users to set up the CMS with attacker-controlled parameters.
  remediation: |
    Complete the installation process immediately or restrict access to the installation page.
  reference:
    - https://basercms.net/
  classification:
    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
    cvss-score: 9.4
    cwe-id: CWE-284
  metadata:
    max-request: 1
    verified: true
    product: baserCMS
    shodan-query: http.favicon.hash:-236105569
    fofa-query: app="baserCMS"
  tags: misconfig,install,basercms,cms,exposure,vuln

http:
  - method: GET
    path:
      - "{{BaseURL}}"

    host-redirects: true
    max-redirects: 2
    matchers-condition: and
    matchers:
      - type: word
        part: body
        words:
          - "basercms"
          - "<form action=\"/installations/step"
        condition: and
        case-insensitive: true

      - type: status
        status:
          - 200
# digest: 4a0a0047304502207a30a31ce17e80b95e75d5377ef98a93e06a15183ec932e1c647d5301285d4f2022100f8a885ab238856b5af0276fb8783f8ad41fdff1d6eb5a65944ac9fd7a4943c4f:922c64590222798bb761d5b6d8e72950