First published: Thu Dec 19 2019(Updated: )
An issue was discovered in Backdrop CMS 1.14.x before 1.14.2. It doesn't sufficiently filter output when displaying file type descriptions created by administrators. An attacker could potentially craft a specialized description, then have an administrator execute scripting when viewing the list of file types, aka XSS. This vulnerability is mitigated by the fact that an attacker must have a role with the "Administer file types" permission.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Backdrop CMS | >=1.13.0<1.13.5 | |
Backdrop CMS | >=1.14.0<1.14.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-19903 is a vulnerability discovered in Backdrop CMS 1.14.x before 1.14.2 that allows an attacker to execute scripting when viewing a list of file type descriptions created by administrators.
CVE-2019-19903 impacts Backdrop CMS by not sufficiently filtering output, which can allow an attacker to craft a specialized description to execute scripting.
The severity of CVE-2019-19903 is medium with a CVSS score of 4.8.
To fix CVE-2019-19903 in Backdrop CMS, you should update to version 1.14.2 or later.
You can find more information about CVE-2019-19903 in the security advisory at https://backdropcms.org/security/backdrop-sa-core-2019-015.