Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-41709

Опубликовано: 22 июл. 2024
Источник: debian

Описание

Backdrop CMS before 1.27.3 and 1.28.x before 1.28.2 does not sufficiently sanitize field labels before they are displayed in certain places. This vulnerability is mitigated by the fact that an attacker must have a role with the "administer fields" permission.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
backdropitppackage

Связанные уязвимости

CVSS3: 4.8
nvd
больше 1 года назад

Backdrop CMS before 1.27.3 and 1.28.x before 1.28.2 does not sufficiently sanitize field labels before they are displayed in certain places. This vulnerability is mitigated by the fact that an attacker must have a role with the "administer fields" permission.

CVSS3: 4.8
github
больше 1 года назад

Backdrop CMS does not sufficiently sanitize field labels before they are displayed in certain places