CVE-2022-42096: XSS
Published Nov 21, 2022
·Updated
Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via Post content.
Affected Software
2 affected components
BackdropCMS Backdrop Cms=1.23.0
composer/backdrop/backdrop<=1.23.0
Event History
Nov 21, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Advisory Published
via GitHub·09:30 PM
Data Sourced
via GitHub·09:30 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of the stored cross-site scripting (XSS) vulnerability in Backdrop CMS?
The vulnerability ID is CVE-2022-42096.
2
What is the severity of CVE-2022-42096?
The severity of CVE-2022-42096 is medium with a CVSS score of 4.8.
3
How does the vulnerability occur in Backdrop CMS?
The vulnerability occurs in Backdrop CMS version 1.23.0 via Post content and allows for stored cross-site scripting (XSS) attacks.
4
Is there a fix available for CVE-2022-42096?
Yes, a fix is available by updating to a version of Backdrop CMS that is not affected by the vulnerability.
5
Where can I find more information about CVE-2022-42096?
You can find more information about CVE-2022-42096 on the Backdrop CMS website and the GitHub release page for version 1.23.0.