JavaScript Execution Vulnerability in Backdrop CMS by Backdrop
CVE-2019-14770

6.1MEDIUM

Key Information:

Vendor
CVE Published:
8 August 2019

What is CVE-2019-14770?

In Backdrop CMS versions prior to 1.12.8 and 1.13.3, a vulnerability allows crafted menu links in the administration bar to execute JavaScript code when the administrator is logged in and utilizing the search feature. While the impact is limited by the requirement for the attacker to have permissions to create administrative menu links—which typically are granted to trusted users or administrators—this flaw poses significant risks if exploited.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2019-14770 : JavaScript Execution Vulnerability in Backdrop CMS by Backdrop