First published: Thu Feb 03 2022(Updated: )
** DISPUTED ** A Cross Site Request Forgery (CSRF) vulnerability exists in Backdrop CMS 1.20, which allows Remote Attackers to gain Remote Code Execution (RCE) on the Hosting Webserver via uploading a maliciously add-on with crafted PHP file. NOTE: the vendor disputes this because the attack requires a session cookie of a high-privileged authenticated user who is entitled to install arbitrary add-ons.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Backdrop CMS | =1.20.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Backdrop CMS vulnerability is CVE-2021-45268.
The severity of CVE-2021-45268 is high (8.8).
The affected software version of CVE-2021-45268 is Backdrop CMS 1.20.0.
The CWE ID for this vulnerability is CWE-352.
An attacker can exploit this vulnerability by uploading a malicious add-on with a crafted PHP file.