
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-30878 is a mail form acceptance bypass vulnerability in baserCMS, a PHP-based website development framework. Prior to version 5.2.3, a public mail submission API endpoint allows unauthenticated users to submit mail form entries even when the corresponding form has been administratively disabled or closed. The vulnerability was published on March 30–31, 2026, and patched in version 5.2.3. It carries a CVSS v3.1 base score of 5.3 (Medium) (GitHub Advisory, baserCMS Security).
The root cause is improper authorization (CWE-285): the public API endpoint plugins/bc-mail/src/Controller/Api/MailMessagesController.php::add() does not invoke the MailFrontService::isAccepting() check that is enforced in the front-end UI flow via MailController::index() and MailController::confirm(). As a result, the API accepts mail form submissions regardless of the form's configured acceptance state (e.g., outside its publish window or explicitly closed by an administrator). Exploitation requires no authentication — only a valid CSRF cookie and token pair obtained by a simple GET request to the site root is sufficient to submit a POST request to /baser/api/bc-mail/mail_messages/add/<form_id>.json (GitHub Advisory).
Successful exploitation allows unauthenticated remote attackers to bypass administrative controls and submit mail form entries to a disabled or closed form, enabling spam campaigns, operational disruption, and abuse of the site's mail infrastructure. There is no confidentiality or availability impact; the integrity impact is limited to unauthorized data insertion into the mail message store. Administrators who rely on form acceptance settings for maintenance windows, incident response, or spam mitigation are directly undermined by this bypass (GitHub Advisory).
A proof-of-concept exploit consisting of concrete curl commands is publicly documented in the official GitHub Security Advisory, demonstrating the full exploitation sequence including CSRF token acquisition and API submission (GitHub Advisory). There is no evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The EPSS score is approximately 0.047% (0.02% per GitHub Advisory), indicating a low near-term exploitation probability. No threat actor attribution has been reported.
curl -sS -D - -o - -c /tmp/basercms_cookies.txt 'http://<target>/'csrfToken value from the saved cookie file (/tmp/basercms_cookies.txt).curl -sS -D - -o - -X POST 'http://<target>/baser/api/bc-mail/mail_messages/add/1.json' \
-H 'Content-Type: application/x-www-form-urlencoded' \
-H 'Referer: http://<target>/' \
-H 'X-CSRF-Token: <extracted_token>' \
-b /tmp/basercms_cookies.txt \
--data-urlencode 'name_1=Test' \
--data-urlencode 'name_2=User' \
--data-urlencode 'email_1=attacker@example.com' \
--data-urlencode 'email_2=attacker@example.com' \
--data-urlencode 'message=Spam or abuse content'200 OK response confirms the mail message was created despite the form being closed, achieving unauthorized mail submission (GitHub Advisory)./baser/api/bc-mail/mail_messages/add/<id>.json from unauthenticated or unknown IP addresses, especially when the corresponding mail form is administratively disabled.MailMessagesController API endpoint with 200 OK responses during periods when the form should be rejecting submissions; requests originating from automated tools (e.g., curl user-agent strings).mail_messages table) timestamped during form closure periods.Upgrade baserCMS to version 5.2.3 or later, which patches this vulnerability by adding the MailFrontService::isAccepting() check to the public API endpoint (baserCMS Release, baserCMS Security). As a temporary workaround until patching is possible, implement network-level access controls (e.g., WAF rules or firewall policies) to restrict access to the /baser/api/bc-mail/mail_messages/add/ endpoint, or disable the API entirely if not required for legitimate use. Organizations should also monitor mail message logs for anomalous submissions during form closure periods.
The vulnerability was reported by security researcher melonattacker and disclosed responsibly through the baserCMS GitHub Security Advisory process. The baserCMS development team patched the issue in version 5.2.3, released on March 26, 2026, alongside eight other CVEs including OS command injection and XSS vulnerabilities (baserCMS Release). No significant broader media coverage or notable social media discussion has been identified beyond standard vulnerability database aggregation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."