Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-12755
HistoryFeb 16, 2022 - 12:00 a.m.

Backdrop CMS Cross-Site Request Forgery Vulnerability

2022-02-1600:00:00
China National Vulnerability Database
www.cnvd.org.cn
7
backdrop cms
cross-site request forgery
vulnerability
remote code execution
malicious add-on

EPSS

0.008

Percentile

82.4%

Backdrop CMS is an open source content management system (CMS). A cross-site request forgery vulnerability exists in Backdrop CMS, which stems from obtaining remote code execution (RCE) on a hosted web server by uploading a malicious add-on with a crafted PHP file. No details of the vulnerability are currently available.

EPSS

0.008

Percentile

82.4%

Related for CNVD-2022-12755