6.1
CVE-2024-41709
- EPSS 0.34%
- Veröffentlicht 22.07.2024 06:15:02
- Zuletzt bearbeitet 21.03.2025 21:15:35
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Backdrop CMS before 1.27.3 and 1.28.x before 1.28.2 does not sufficiently sanitize field labels before they are displayed in certain places. This vulnerability is mitigated by the fact that an attacker must have a role with the "administer fields" permission.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Backdropcms ≫ Backdrop Version >= 1.27.0 < 1.27.3
Backdropcms ≫ Backdrop Version >= 1.28.0 < 1.28.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.34% | 0.562 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.8 | 1.7 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 6.1 | 2.8 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.