Input validation error in Backdrop CMS - #VU19980

 

Input validation error in Backdrop CMS - #VU19980

Published: August 8, 2019


Vulnerability identifier: #VU19980
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise vulnerable website.

The vulnerability exists due to insufficient validation of the uploaded files. A remote privileged attacker can upload and execute arbitrary PHP code on the server.

Successful exploitation of the vulnerability requires "Synchronize, import, and export configuration" permissions. 


Affected software

Backdrop CMS

Remediation

Install updates from vendor's website.

Backdrop CMS - addressed in versions 1.12.8, 1.13.3

External References

Related Security Bulletins