File Upload Vulnerability in Backdrop CMS by Backdrop
CVE-2019-14771
9.8CRITICAL
What is CVE-2019-14771?
Backdrop CMS versions 1.12.x prior to 1.12.8 and 1.13.x prior to 1.13.3 have a file upload vulnerability that allows unauthorized upload of configuration archives via the user interface or command line. The vulnerability occurs due to insufficient validation of uploaded archives, potentially enabling the upload of non-configuration scripts to the server. While an attacker would need the 'Synchronize, import, and export configuration' permission to exploit this vulnerability—permissions generally restricted to trusted administrators—potential security risks still exist if other server-side scripting languages become accessible.