JavaScript Execution Vulnerability in Backdrop CMS by Backdrop
CVE-2019-14770
6.1MEDIUM
What is CVE-2019-14770?
In Backdrop CMS versions prior to 1.12.8 and 1.13.3, a vulnerability allows crafted menu links in the administration bar to execute JavaScript code when the administrator is logged in and utilizing the search feature. While the impact is limited by the requirement for the attacker to have permissions to create administrative menu links—which typically are granted to trusted users or administrators—this flaw poses significant risks if exploited.