SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2024-41709

This vulnerability is mitigated by the fact that an attacker must have a role with the "administer fields" permission.

MEDIUM 4.8EPSS 0.32%

Does this matter?

Lower severity and a low EPSS score (0.32%). Track it; it rarely justifies an emergency change on its own.

Description

Backdrop CMS before 1.27.3 and 1.28.x before 1.28.2 does not sufficiently sanitize field labels before they are displayed in certain places. This vulnerability is mitigated by the fact that an attacker must have a role with the "administer fields" permission.

CVSS 3.1
4.8 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
EPSS
0.32% probability · 24th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
backdropcms/backdrop
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.