Beveiligingsadvies

CVE-2024-41709

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2024-07-22 00:00:00
Laatst bijgewerkt 2025-03-21 20:51:26
Toegewezen door mitre
CVSS-score 6.1
Status PUBLISHED

Beschrijving

Backdrop CMS before 1.27.3 and 1.28.x before 1.28.2 does not sufficiently sanitize field labels before they are displayed in certain places. This vulnerability is mitigated by the fact that an attacker must have a role with the "administer fields" permission.