In baserCMS before 4.1.4, lib\Baser\Model\ThemeConfig.php allows remote attackers to execute arbitrary PHP code via the admin/theme_configs/form data[ThemeConfig][logo] parameter.
{
"github_reviewed_at": "2023-07-07T18:19:54Z",
"cwe_ids": [
"CWE-434"
],
"severity": "HIGH",
"nvd_published_at": "2018-11-05T09:29:00Z",
"github_reviewed": true
}