baserCMS version 3.0.14 and earlier, 4.0.5 and earlier allows remote attackers to delete arbitrary files via unspecified vectors when the "File" field is being used in the mail form.
| Software | From | Fixed in |
|---|---|---|
| basercms / basercms | 3.0.0 | 3.0.14.x |
| basercms / basercms | 4.0.0 | 4.0.5.x |