Product
Authenticated administrators can exploit a SQL injection vulnerability in baserCMS versions prior to 5.3.0, chaining it with a secondary code injection flaw to extract sensitive data and execute arbitrary PHP code.