CVE-2026-30880: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-30880 is an OS command injection vulnerability in the installer component of baserCMS, a PHP-based website development framework. The flaw affects baserCMS versions 5.2.2 and earlier, and was disclosed on March 30–31, 2026, with a patch released in version 5.2.3. It carries a CVSS v3.1 base score of 9.8 (Critical) and a CVSS v4.0 base score of 9.2 (Critical) (GitHub Advisory, baserproject Advisory). The vulnerability was credited to researcher REN XINGDIAN and is tracked under GHSA-6hpg-8rx3-cwgv (GitHub Advisory).

Technical details

The vulnerability is classified as CWE-78 (Improper Neutralization of Special Elements used in an OS Command), meaning the baserCMS installer fails to properly sanitize user-supplied input before passing it to OS-level command execution functions (GitHub Advisory). The attack vector is network-based, requires no authentication or user interaction, and no special privileges — however, exploitation requires that baserCMS has been deployed on a server but not yet completed the installation process (baserproject Advisory). The CVSS v4.0 rating notes High Attack Complexity, reflecting that the specific pre-installation state of the application must be present for exploitation to succeed. No public proof-of-concept code has been identified at this time (GitHub Advisory).

Impact

Successful exploitation allows an unauthenticated remote attacker to execute arbitrary OS commands on the affected server, resulting in full compromise of confidentiality, integrity, and availability of the vulnerable system (baserproject Advisory). This could enable unauthorized access to sensitive data stored on the server, modification or deletion of system files, installation of backdoors or malware, and potential lateral movement within the network (GitHub Advisory). The scope of impact is limited to the vulnerable system itself (no subsequent system impact per CVSS v4.0 metrics), but the ability to run arbitrary commands as the web server process makes this a severe risk for any organization with an uninstalled baserCMS instance exposed to the network.

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (GitHub Advisory). The EPSS score is approximately 0.057% (18th percentile), indicating a low near-term probability of exploitation (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no threat actor attribution has been reported. The key precondition — that baserCMS must be deployed but not yet installed — limits the attack surface to a relatively narrow window during initial setup.

Exploitation steps

  1. Reconnaissance: Use internet scanning tools (e.g., Shodan, Censys, or Google dorks) to identify publicly accessible servers running baserCMS version 5.2.2 or earlier that are in an uninstalled/setup state, typically identifiable by the presence of the installer interface at a known URL path.
  2. Identify installer endpoint: Navigate to the baserCMS installer URL (e.g., /install or equivalent setup endpoint) to confirm the application is in the pre-installation state and the vulnerable installer component is accessible.
  3. Craft malicious input: Prepare a request containing OS command injection payloads (e.g., using shell metacharacters such as ;, |, &&, or backticks) embedded in installer form fields that are passed to OS command execution functions without proper sanitization.
  4. Submit payload: Send the crafted HTTP request to the installer endpoint, injecting the malicious OS command into the vulnerable parameter.
  5. Achieve code execution: The injected command executes on the server as the web server process user, enabling the attacker to establish a reverse shell, exfiltrate data, create persistent access, or perform further actions on the compromised host (baserproject Advisory, GitHub Advisory).

Indicators of compromise

  • Network: Unexpected HTTP POST requests to baserCMS installer endpoints (e.g., /install, /setup) from external or unknown IP addresses; outbound connections from the web server to external hosts following installer access.
  • Logs: Web server access logs showing requests to installer paths with unusual or encoded parameter values containing shell metacharacters (;, |, &&, backticks); error logs showing unexpected command execution or shell process spawning.
  • Process: Unusual child processes spawned by the PHP or web server process (e.g., /bin/sh, /bin/bash, curl, wget, python, nc) during or after installer access.
  • File System: Newly created files in the baserCMS web root or temporary directories, particularly web shells (.php files with obfuscated content), cron job modifications, or SSH authorized_keys changes made by the web server user.

Mitigation and workarounds

The primary remediation is to update baserCMS to version 5.2.3 or later, which patches this vulnerability along with several other critical issues disclosed simultaneously (GitHub Release, GitHub Advisory). As an immediate workaround, organizations should implement network access controls to restrict access to the baserCMS installer endpoint to trusted IP addresses only, or take the installer offline if the application is not actively being set up. Any baserCMS instance that has been deployed but not yet installed should be treated as high-priority for patching or network isolation (baserproject Advisory).

Community reactions

The vulnerability was mentioned in a Loginsoft Medium post covering active exploits and supply chain attacks from late March to early April 2026, grouping it with other notable vulnerabilities of that period. Social media activity was observed on Bluesky and Mastodon (infosec.exchange) shortly after disclosure, primarily consisting of automated CVE notification posts. No significant independent researcher commentary or major media coverage specific to this CVE has been identified beyond standard vulnerability database aggregation.

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management