CVE-2019-14769: XSS
Backdrop CMS 1.12.x before 1.12.8 and 1.13.x before 1.13.3 doesn't sufficiently filter output when displaying certain block labels created by administrators. An attacker could potentially craft a specialized label, then have an administrator execute scripting when administering a layout. (This issue is mitigated by the attacker needing permission to create custom blocks on the site, which is typically an administrative permission.)
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-14769?
CVE-2019-14769 is a vulnerability in Backdrop CMS versions 1.12.x before 1.12.8 and 1.13.x before 1.13.3 that allows an attacker to craft a specialized label to execute scripting when administering a layout.
How does CVE-2019-14769 affect Backdrop CMS?
CVE-2019-14769 affects Backdrop CMS versions 1.12.x before 1.12.8 and 1.13.x before 1.13.3 by not sufficiently filtering output when displaying certain block labels created by administrators.
What is the severity of CVE-2019-14769?
The severity of CVE-2019-14769 is medium with a CVSS score of 6.1.
How can I fix CVE-2019-14769?
To fix CVE-2019-14769, update your Backdrop CMS to version 1.12.8 or 1.13.3.
Where can I find more information about CVE-2019-14769?
You can find more information about CVE-2019-14769 in the Backdrop CMS security advisory SA-CORE-2019-011 at https://backdropcms.org/security/backdrop-sa-core-2019-011.