File Upload Vulnerability in Backdrop CMS by Backdrop
CVE-2019-14771

9.8CRITICAL

Key Information:

Vendor
CVE Published:
8 August 2019

What is CVE-2019-14771?

Backdrop CMS versions 1.12.x prior to 1.12.8 and 1.13.x prior to 1.13.3 have a file upload vulnerability that allows unauthorized upload of configuration archives via the user interface or command line. The vulnerability occurs due to insufficient validation of uploaded archives, potentially enabling the upload of non-configuration scripts to the server. While an attacker would need the 'Synchronize, import, and export configuration' permission to exploit this vulnerability—permissions generally restricted to trusted administrators—potential security risks still exist if other server-side scripting languages become accessible.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2019-14771 : File Upload Vulnerability in Backdrop CMS by Backdrop