← Back

CVE-2024-41709

nvd nist
Published: Jul 22, 2024Modified: Jun 17, 2026

JSON object

Loading...
4.8
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Exploitability: 1.7 / Impact: 2.7
Source: NVD

Description

Backdrop CMS before 1.27.3 and 1.28.x before 1.28.2 does not sufficiently sanitize field labels before they are displayed in certain places. This vulnerability is mitigated by the fact that an attacker must have a role with the "administer fields" permission.

Affected (2)

1 product
Backdrop
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Backdropcms
From 1.27.0 to 1.27.3
From 1.28.0 to 1.28.2

References (2)

Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.