CVE-2024-54123: XSS
Backdrop CMS before 1.28.4 and 1.29.x before 1.29.2 allows XSS via an SVG document, if the SVG tag is allowed for a text format.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-54123?
CVE-2024-54123 has been classified as a high severity vulnerability due to its potential for exploitation via cross-site scripting (XSS).
How do I fix CVE-2024-54123?
To fix CVE-2024-54123, upgrade Backdrop CMS to version 1.28.4 or 1.29.2 or later, where the vulnerability has been addressed.
What are the risks associated with CVE-2024-54123?
The risks associated with CVE-2024-54123 include unauthorized access and data manipulation through XSS attacks that target vulnerable SVG tags.
Which versions of Backdrop CMS are affected by CVE-2024-54123?
Backdrop CMS versions prior to 1.28.4 and 1.29.x before 1.29.2 are affected by CVE-2024-54123.
Can CVE-2024-54123 be exploited without user interaction?
Yes, CVE-2024-54123 can potentially be exploited without user interaction if the SVG document is rendered in a vulnerable environment.