Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3wmx-48g3-x66g

Опубликовано: 22 июл. 2024
Источник: github
Github: Прошло ревью
CVSS4: 4.6
CVSS3: 4.8

Описание

Backdrop CMS does not sufficiently sanitize field labels before they are displayed in certain places

Backdrop CMS before 1.27.3 and 1.28.x before 1.28.2 does not sufficiently sanitize field labels before they are displayed in certain places. This vulnerability is mitigated by the fact that an attacker must have a role with the "administer fields" permission.

Пакеты

Наименование

backdrop/backdrop

composer
Затронутые версииВерсия исправления

< 1.27.3

1.27.3

Наименование

backdrop/backdrop

composer
Затронутые версииВерсия исправления

>= 1.28.0, < 1.28.2

1.28.2

EPSS

Процентиль: 56%
0.00341
Низкий

4.6 Medium

CVSS4

4.8 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 4.8
nvd
больше 1 года назад

Backdrop CMS before 1.27.3 and 1.28.x before 1.28.2 does not sufficiently sanitize field labels before they are displayed in certain places. This vulnerability is mitigated by the fact that an attacker must have a role with the "administer fields" permission.

CVSS3: 4.8
debian
больше 1 года назад

Backdrop CMS before 1.27.3 and 1.28.x before 1.28.2 does not sufficien ...

EPSS

Процентиль: 56%
0.00341
Низкий

4.6 Medium

CVSS4

4.8 Medium

CVSS3

Дефекты

CWE-79