Cross-Site Scripting in Backdrop CMS Affects Administrators
CVE-2019-19903

4.8MEDIUM

Key Information:

Vendor
CVE Published:
19 December 2019

What is CVE-2019-19903?

A Cross-Site Scripting vulnerability exists in Backdrop CMS versions 1.14.x prior to 1.14.2, arising from insufficient output filtering in file type descriptions created by administrators. This flaw allows an attacker with the 'Administer file types' permission to inject malicious scripts, which could then be executed when an administrator views the list of file types. Proper input validation and output encoding measures are essential to mitigate this risk.

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.