Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-86397
HistoryNov 24, 2022 - 12:00 a.m.

Backdrop CMS Comment Cross-Site Scripting Vulnerability

2022-11-2400:00:00
China National Vulnerability Database
www.cnvd.org.cn
7
backdrop cms
cross-site scripting
vulnerability
user-supplied data
filtering

EPSS

0.001

Percentile

44.3%

Backdrop CMS is an open source content management system (CMS). version 1.23.0 of Backdrop CMS Comment is vulnerable to a cross-site scripting vulnerability that results from a lack of effective filtering and escaping of user-supplied data, which could be exploited to launch a cross-site scripting (XSS) attack.

EPSS

0.001

Percentile

44.3%