Vulnerability Description
The Borg theme before 1.1.19 for Backdrop CMS does not sufficiently sanitize path arguments that are passed in via a URL. The function borg_preprocess_page in the file template.php does not properly sanitize incoming path arguments before using them.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Borg Project | Borg | < 1.1.19 |
Related Weaknesses (CWE)
References
- https://backdropcms.org/project/borgProduct
- https://github.com/backdrop-contrib/borg/compare/1.x-1.1.18...1.x-1.1.19Patch
- https://backdropcms.org/project/borgProduct
- https://github.com/backdrop-contrib/borg/compare/1.x-1.1.18...1.x-1.1.19Patch
FAQ
What is CVE-2023-26265?
CVE-2023-26265 is a vulnerability with a CVSS score of 5.3 (MEDIUM). The Borg theme before 1.1.19 for Backdrop CMS does not sufficiently sanitize path arguments that are passed in via a URL. The function borg_preprocess_page in the file template.php does not properly s...
How severe is CVE-2023-26265?
CVE-2023-26265 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-26265?
Check the references section above for vendor advisories and patch information. Affected products include: Borg Project Borg.