Stored Cross-site Scripting Vulnerability in Backdrop CMS by Backdrop
CVE-2023-31045
4.8MEDIUM
What is CVE-2023-31045?
A vulnerability in Backdrop CMS prior to version 1.24.2 allows remote attackers to exploit a stored Cross-site Scripting (XSS) flaw affecting the text editors and formats feature. An attacker can inject arbitrary web scripts or HTML through the 'name' parameter during content type edits. When an administrator selects a user-configured malicious text formatting option, the harmful payload is executed, leading to potential unauthorized actions and data compromise. While the vendor questions the significance of the finding, this vulnerability poses a risk to users relying on secure text formatting configurations.