backdropcms.org
https://backdropcms.org/security/backdrop-sa-core-2024-001 CVE-2024-41709
Backdrop CMS does not sufficiently sanitize field labels before they are displayed in certain places
Description
Backdrop CMS before 1.27.3 and 1.28.x before 1.28.2 does not sufficiently sanitize field labels before they are displayed in certain places. This vulnerability is mitigated by the fact that an attacker must have a role with the "administer fields" permission.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 23, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
backdrop/backdropBrowse Packagist / backdrop/backdrop | GitHub Advisory | Before 1.27.3 · Fixed in 1.27.3 | affected |
| 1.28.0 to < 1.28.2 · Fixed in 1.28.2 | affected |
References
5github.com
https://github.com/backdrop-ops/backdrop-composer github.com
https://github.com/backdrop/backdrop/commit/c7ff0500705668e3f58263590812872e44059301 github.com
https://github.com/backdrop/backdrop/commit/f1dfe710c186fb47c9d949f01f37e5ab42b44030 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-41709