Stored Cross-Site Scripting Vulnerability in BackdropCMS by Backdrop
CVE-2022-24590

5.4MEDIUM

Key Information:

Status
Vendor
CVE Published:
15 February 2022

What is CVE-2022-24590?

A stored cross-site scripting vulnerability exists within the Add Link function of BackdropCMS v1.21.1. This flaw allows attackers to inject and execute arbitrary web scripts or HTML, potentially compromising user sessions and leading to unauthorized access or data manipulation. Proper validation and sanitization of user inputs in this function are vital to mitigating this risk. Organizations utilizing BackdropCMS must ensure that they apply necessary security patches and implement security best practices to safeguard against exploitation.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.