CVE-2026-45430: CSRF
Published May 12, 2026
·Updated
The Salesforce module before 1.x-1.0.1 for Backdrop CMS does not properly use a random state parameter to protect the authorization flow against CSRF attacks.
Affected Software
1 affected component
Backdrop CMS Salesforce module<1.x-1.0.1
Event History
May 12, 2026
CVE Published
via MITRE·04:06 AM
Data Sourced
via MITRE·04:06 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-45430?
CVE-2026-45430 is classified as a moderate severity vulnerability due to its potential for CSRF attacks.
2
How does CVE-2026-45430 affect Backdrop CMS users?
CVE-2026-45430 affects users of the Salesforce module in Backdrop CMS by exposing them to possible unauthorized actions via CSRF exploits.
3
How do I fix CVE-2026-45430?
To fix CVE-2026-45430, update the Salesforce module to version 1.x-1.0.1 or later.
4
What is a CSRF attack in the context of CVE-2026-45430?
A CSRF attack involving CVE-2026-45430 is a malicious request that tricks a user into unintentionally submitting requests to the Backdrop CMS.
5
Is CVE-2026-45430 present in older versions of the Salesforce module?
Yes, CVE-2026-45430 is present in all versions of the Salesforce module for Backdrop CMS prior to 1.x-1.0.1.