PT-2023-23121 · Unknown · Backdrop Cms

Jenlampton

·

Published

2023-04-24

·

Updated

2024-08-02

·

CVE-2023-31045

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Backdrop CMS versions prior to 1.24.2
Description A stored Cross-site scripting (XSS) issue in Text Editors and Formats allows remote attackers to inject arbitrary web script or HTML via the name parameter. When a user is editing any content type as an admin, the stored XSS payload is executed upon selecting a malicious text formatting option. The vendor disputes the security relevance of this finding.
Recommendations For Backdrop CMS versions prior to 1.24.2, update to version 1.24.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the text formatting options to minimize the risk of exploitation. Avoid using the name parameter in the affected text editing functionality until the issue is resolved.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-31045
GHSA-3862-C622-V4FP

Affected Products

Backdrop Cms