First published: Mon Jul 22 2024(Updated: )
Backdrop CMS before 1.27.3 and 1.28.x before 1.28.2 does not sufficiently sanitize field labels before they are displayed in certain places. This vulnerability is mitigated by the fact that an attacker must have a role with the "administer fields" permission.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/backdrop/backdrop | >=1.28.0<1.28.2 | 1.28.2 |
composer/backdrop/backdrop | <1.27.3 | 1.27.3 |
Backdrop | >=1.27.0<1.27.3 | |
Backdrop | >=1.28.0<1.28.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-41709 has a moderate severity due to improper sanitization of field labels which can lead to potential exposure of sensitive information.
To resolve CVE-2024-41709, upgrade your Backdrop CMS version to 1.27.3 or 1.28.2.
CVE-2024-41709 affects users of Backdrop CMS versions prior to 1.27.3 and versions between 1.28.0 and 1.28.1.
The vulnerability can allow attackers with administrative field permissions to display unsanitized field labels, leading to potential XSS attacks.
Yes, an attacker must have the 'administer fields' permission to exploit CVE-2024-41709.