Vulnerability Description
Backdrop CMS before 1.27.3 and 1.28.x before 1.28.2 does not sufficiently sanitize field labels before they are displayed in certain places. This vulnerability is mitigated by the fact that an attacker must have a role with the "administer fields" permission.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Backdropcms | Backdrop | >= 1.27.0, < 1.27.3 |
Related Weaknesses (CWE)
References
- https://backdropcms.org/security/backdrop-sa-core-2024-001Vendor Advisory
- https://backdropcms.org/security/backdrop-sa-core-2024-001Vendor Advisory
FAQ
What is CVE-2024-41709?
CVE-2024-41709 is a vulnerability with a CVSS score of 4.8 (MEDIUM). Backdrop CMS before 1.27.3 and 1.28.x before 1.28.2 does not sufficiently sanitize field labels before they are displayed in certain places. This vulnerability is mitigated by the fact that an attacke...
How severe is CVE-2024-41709?
CVE-2024-41709 has been rated MEDIUM with a CVSS base score of 4.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-41709?
Check the references section above for vendor advisories and patch information. Affected products include: Backdropcms Backdrop.