Security Advisory
CVE-2011-2674
CVE vulnerability detail - eXtreme Datacenter Security Operations
Description
BaserCMS before 1.6.12 does not properly restrict additions to the membership of the operators group, which allows remote authenticated users to gain privileges via unspecified vectors.