CVE-2019-14770: XSS
In Backdrop CMS 1.12.x before 1.12.8 and 1.13.x before 1.13.3, some menu links within the administration bar may be crafted to execute JavaScript when the administrator is logged in and uses the search functionality. (This issue is mitigated by the attacker needing permissions to create administrative menu links, such as by creating a content type or layout. Such permissions are usually restricted to trusted or administrative users.)
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2019-14770.
What is the severity of CVE-2019-14770?
The severity of CVE-2019-14770 is medium (6.1).
Which version of Backdrop CMS is affected by CVE-2019-14770?
Backdrop CMS versions 1.12.x before 1.12.8 and 1.13.x before 1.13.3 are affected by CVE-2019-14770.
How does CVE-2019-14770 affect the administration bar in Backdrop CMS?
CVE-2019-14770 allows crafted menu links within the administration bar to execute JavaScript when the administrator is logged in and uses the search functionality.
Is there a mitigation for CVE-2019-14770?
The issue is partially mitigated by requiring the attacker to have permissions to create administrative menu links.