PT-2022-7178 · Unknown · Backdrop Cms

Grim The Ripper Team

·

Published

2022-11-22

·

Updated

2025-04-28

·

CVE-2022-42095

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Backdrop CMS version 1.23.0
Description The issue is related to the lack of protection for the web page structure in Backdrop CMS, which can be exploited by a remote attacker to conduct cross-site scripting (XSS) attacks. Specifically, it is a stored XSS vulnerability that can be triggered via the Page content.
Recommendations For Backdrop CMS version 1.23.0, update to a version that includes a fix for this issue to prevent stored cross-site scripting attacks. As a temporary workaround, consider restricting access to the Page content feature until a patch is available.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2023-08732
CVE-2022-42095
GHSA-58RJ-W2QF-QJG7

Affected Products

Backdrop Cms