CVE-2024-54123Cross-site Scripting in Backdrop CMS

Severity
6.1MEDIUMNVD
EPSS
0.4%
top 38.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 29

Description

Backdrop CMS before 1.28.4 and 1.29.x before 1.29.2 allows XSS via an SVG document, if the SVG tag is allowed for a text format.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages1 packages

NVDbackdropcms/backdrop_cms1.29.01.29.2+1

🔴Vulnerability Details

2
CVEList
CVE-2024-54123: Backdrop CMS before 12024-11-29
GHSA
GHSA-6gqq-xj74-45f9: Backdrop CMS before 12024-11-29
CVE-2024-54123 — Cross-site Scripting in Backdrop CMS | cvebase