Описание
Backdrop CMS before 1.27.3 and 1.28.x before 1.28.2 does not sufficiently sanitize field labels before they are displayed in certain places. This vulnerability is mitigated by the fact that an attacker must have a role with the "administer fields" permission.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| backdrop | itp | package |
EPSS
Процентиль: 24%
0.00315
Низкий
Связанные уязвимости
CVSS3: 4.8
nvd
около 2 лет назад
Backdrop CMS before 1.27.3 and 1.28.x before 1.28.2 does not sufficiently sanitize field labels before they are displayed in certain places. This vulnerability is mitigated by the fact that an attacker must have a role with the "administer fields" permission.
CVSS3: 4.8
github
около 2 лет назад
Backdrop CMS does not sufficiently sanitize field labels before they are displayed in certain places
EPSS
Процентиль: 24%
0.00315
Низкий