Stored Cross-Site Scripting Vulnerability in BackdropCMS by Backdrop
CVE-2022-24590
5.4MEDIUM
What is CVE-2022-24590?
A stored cross-site scripting vulnerability exists within the Add Link function of BackdropCMS v1.21.1. This flaw allows attackers to inject and execute arbitrary web scripts or HTML, potentially compromising user sessions and leading to unauthorized access or data manipulation. Proper validation and sanitization of user inputs in this function are vital to mitigating this risk. Organizations utilizing BackdropCMS must ensure that they apply necessary security patches and implement security best practices to safeguard against exploitation.