PT-2019-15994 · Backdrop · Backdrop Cms

Bot Kotatu

·

Published

2019-12-19

·

Updated

2019-12-27

·

CVE-2019-19900

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Backdrop CMS versions 1.13.x through 1.13.4 Backdrop CMS versions 1.14.x through 1.14.1
Description An issue was discovered that allows for potential XSS attacks when displaying content type names in the content creation interface. The software does not sufficiently filter output, which could be exploited by an attacker crafting a specialized content type name to execute scripting when an editor creates content. This issue is mitigated by the requirement that an attacker must have a role with the "Administer content types" permission.
Recommendations For Backdrop CMS versions 1.13.x through 1.13.4, update to version 1.13.5 or later. For Backdrop CMS versions 1.14.x through 1.14.1, update to version 1.14.2 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-19900

Affected Products

Backdrop Cms