Логотип exploitDog
bind:CVE-2019-19901
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2019-19901

Количество 3

Количество 3

nvd логотип

CVE-2019-19901

около 6 лет назад

An issue was discovered in Backdrop CMS 1.13.x before 1.13.5 and 1.14.x before 1.14.2. It doesn't sufficiently filter output when displaying certain block descriptions created by administrators. An attacker could potentially craft a specialized description, then have an administrator execute scripting when configuring a layout, aka XSS. This issue is mitigated by the fact that the attacker would be required to have the permission to create custom blocks, which is typically an administrative task.

CVSS3: 4.8
EPSS: Низкий
debian логотип

CVE-2019-19901

около 6 лет назад

An issue was discovered in Backdrop CMS 1.13.x before 1.13.5 and 1.14. ...

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-86wq-h57h-6m7w

больше 3 лет назад

An issue was discovered in Backdrop CMS 1.13.x before 1.13.5 and 1.14.x before 1.14.2. It doesn't sufficiently filter output when displaying certain block descriptions created by administrators. An attacker could potentially craft a specialized description, then have an administrator execute scripting when configuring a layout, aka XSS. This issue is mitigated by the fact that the attacker would be required to have the permission to create custom blocks, which is typically an administrative task.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2019-19901

An issue was discovered in Backdrop CMS 1.13.x before 1.13.5 and 1.14.x before 1.14.2. It doesn't sufficiently filter output when displaying certain block descriptions created by administrators. An attacker could potentially craft a specialized description, then have an administrator execute scripting when configuring a layout, aka XSS. This issue is mitigated by the fact that the attacker would be required to have the permission to create custom blocks, which is typically an administrative task.

CVSS3: 4.8
0%
Низкий
около 6 лет назад
debian логотип
CVE-2019-19901

An issue was discovered in Backdrop CMS 1.13.x before 1.13.5 and 1.14. ...

CVSS3: 4.8
0%
Низкий
около 6 лет назад
github логотип
GHSA-86wq-h57h-6m7w

An issue was discovered in Backdrop CMS 1.13.x before 1.13.5 and 1.14.x before 1.14.2. It doesn't sufficiently filter output when displaying certain block descriptions created by administrators. An attacker could potentially craft a specialized description, then have an administrator execute scripting when configuring a layout, aka XSS. This issue is mitigated by the fact that the attacker would be required to have the permission to create custom blocks, which is typically an administrative task.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу