PT-2019-15994 · Backdrop · Backdrop Cms
Bot Kotatu
·
Published
2019-12-19
·
Updated
2019-12-27
·
CVE-2019-19900
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Backdrop CMS versions 1.13.x through 1.13.4
Backdrop CMS versions 1.14.x through 1.14.1
Description
An issue was discovered that allows for potential XSS attacks when displaying content type names in the content creation interface. The software does not sufficiently filter output, which could be exploited by an attacker crafting a specialized content type name to execute scripting when an editor creates content. This issue is mitigated by the requirement that an attacker must have a role with the "Administer content types" permission.
Recommendations
For Backdrop CMS versions 1.13.x through 1.13.4, update to version 1.13.5 or later.
For Backdrop CMS versions 1.14.x through 1.14.1, update to version 1.14.2 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Backdrop Cms