First published: Mon Nov 21 2022(Updated: )
Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via Post content.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Backdrop CMS | =1.23.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-42096.
The severity of CVE-2022-42096 is medium with a CVSS score of 4.8.
The vulnerability occurs in Backdrop CMS version 1.23.0 via Post content and allows for stored cross-site scripting (XSS) attacks.
Yes, a fix is available by updating to a version of Backdrop CMS that is not affected by the vulnerability.
You can find more information about CVE-2022-42096 on the Backdrop CMS website and the GitHub release page for version 1.23.0.