Stored Cross-site Scripting Vulnerability in Backdrop CMS by Backdrop
CVE-2023-31045
What is CVE-2023-31045?
A vulnerability in Backdrop CMS prior to version 1.24.2 allows remote attackers to exploit a stored Cross-site Scripting (XSS) flaw affecting the text editors and formats feature. An attacker can inject arbitrary web scripts or HTML through the 'name' parameter during content type edits. When an administrator selects a user-configured malicious text formatting option, the harmful payload is executed, leading to potential unauthorized actions and data compromise. While the vendor questions the significance of the finding, this vulnerability poses a risk to users relying on secure text formatting configurations.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
