CVE-2024-41709
Backdrop CMS does not sufficiently sanitize field labels before they are displayed in certain places
4.8
MEDIUM
CVSS 3.1
EPSS 0.32%
Description
Backdrop CMS before 1.27.3 and 1.28.x before 1.28.2 does not sufficiently sanitize field labels before they are displayed in certain places. This vulnerability is mitigated by the fact that an attacker must have a role with the "administer fields" permission.
How to fix CVE-2024-41709
To remediate CVE-2024-41709, upgrade the affected package to a fixed version below.
- —upgrade to 1.27.3 or later
Is CVE-2024-41709 being exploited?
Low — EPSS is 0.3%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 1.27.3
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N |
| osv | CVSS 3.1 | MEDIUM4.8 | CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |