CVE-2021-45268: CSRF
Published Feb 3, 2022
·Updated
DISPUTED A Cross Site Request Forgery (CSRF) vulnerability exists in Backdrop CMS 1.20, which allows Remote Attackers to gain Remote Code Execution (RCE) on the Hosting Webserver via uploading a maliciously add-on with crafted PHP file. NOTE: the vendor disputes this because the attack requires a session cookie of a high-privileged authenticated user who is entitled to install arbitrary add-ons.
Affected Software
1 affected component
BackdropCMS Backdrop=1.20.0
Event History
Feb 3, 2022
CVE Published
via MITRE·09:46 PM
Data Sourced
via MITRE·09:46 PM
Description
Disputed
10:15 PM
Frequently Asked Questions
1
What is the vulnerability ID for this Backdrop CMS vulnerability?
The vulnerability ID for this Backdrop CMS vulnerability is CVE-2021-45268.
2
What is the severity of CVE-2021-45268?
The severity of CVE-2021-45268 is high (8.8).
3
What is the affected software version of CVE-2021-45268?
The affected software version of CVE-2021-45268 is Backdrop CMS 1.20.0.
4
What is the CWE ID for this vulnerability?
The CWE ID for this vulnerability is CWE-352.
5
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by uploading a malicious add-on with a crafted PHP file.