Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-42095: [Declined]Backdrop-XSS-at-Pages - GrimTheRipper - Medium

Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Page content.

CVE
#xss#vulnerability

Enter your username and password; the account must have admin privileges.

Select Content > add content > Page

Enter information into the form provided and Enter the XSS payload in the Body field. Choose “Raw HTML” Editor and Save.

The XSS payload will run immediately.

POC:

Related news

GHSA-58rj-w2qf-qjg7: Cross-site Scripting in Backdrop CMS

Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Page content.

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907