CVE-2019-14771Improper Input Validation in Backdrop CMS

Severity
9.8CRITICALNVD
EPSS
1.0%
top 23.27%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 8
Latest updateMay 24

Description

Backdrop CMS 1.12.x before 1.12.8 and 1.13.x before 1.13.3 allows the upload of entire-site configuration archives through the user interface or command line. It does not sufficiently check uploaded archives for invalid data, potentially allowing non-configuration scripts to be uploaded to the server. (This attack is mitigated by the attacker needing the "Synchronize, import, and export configuration" permission, a permission that only trusted administrators should be given. Other preventative m

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages1 packages

NVDbackdropcms/backdrop_cms1.12.01.12.8+1

🔴Vulnerability Details

2
GHSA
GHSA-vcm5-8725-vff8: Backdrop CMS 12022-05-24
CVEList
CVE-2019-14771: Backdrop CMS 12019-08-08
CVE-2019-14771 — Improper Input Validation | cvebase