CVE-2023-31045: XSS
DISPUTED A stored Cross-site scripting (XSS) issue in Text Editors and Formats in Backdrop CMS before 1.24.2 allows remote attackers to inject arbitrary web script or HTML via the name parameter. When a user is editing any content type (e.g., page, post, or card) as an admin, the stored XSS payload is executed upon selecting a malicious text formatting option. NOTE: the vendor disputes the security relevance of this finding because "any administrator that can configure a text format could easily allow Full HTML anywhere."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-31045?
The severity of CVE-2023-31045 is medium with a severity value of 4.8.
How does CVE-2023-31045 affect Backdrop CMS?
CVE-2023-31045 affects Backdrop CMS versions before 1.24.2.
What is the vulnerability type of CVE-2023-31045?
CVE-2023-31045 is a stored Cross-site scripting (XSS) vulnerability.
How can remote attackers exploit CVE-2023-31045?
Remote attackers can exploit CVE-2023-31045 by injecting arbitrary web script or HTML via the name parameter in Text Editors and Formats in Backdrop CMS.
Is there a fix available for CVE-2023-31045?
Yes, the fix for CVE-2023-31045 is available in Backdrop CMS version 1.24.2.