CVE-2019-14769
An attacker could potentially craft a specialized label, then have an administrator execute scripting when administering a layout.
Does this matter?
Lower severity and a low EPSS score (0.85%). Track it; it rarely justifies an emergency change on its own.
Description
Backdrop CMS 1.12.x before 1.12.8 and 1.13.x before 1.13.3 doesn't sufficiently filter output when displaying certain block labels created by administrators. An attacker could potentially craft a specialized label, then have an administrator execute scripting when administering a layout. (This issue is mitigated by the attacker needing permission to create custom blocks on the site, which is typically an administrative permission.)
- CVSS 3.0
- 6.1 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.85% probability · 56th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- backdropcms/backdrop
- Source
- cve@mitre.org
References
- https://backdropcms.org/security/backdrop-sa-core-2019-011Vendor Advisory
- https://backdropcms.org/security/backdrop-sa-core-2019-011Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.