Lucene search

K
cvelistMitreCVELIST:CVE-2019-19902
HistoryDec 19, 2019 - 5:03 a.m.

CVE-2019-19902

2019-12-1905:03:27
mitre
www.cve.org

0.001 Low

EPSS

Percentile

40.4%

An issue was discovered in Backdrop CMS 1.13.x before 1.13.5 and 1.14.x before 1.14.2. It allows the upload of entire-site configuration archives through the user interface or command line. It does not sufficiently check uploaded archives for invalid data, allowing non-configuration scripts to potentially be uploaded to the server. This issue is mitigated by the fact that the attacker would be required to have the โ€œSynchronize, import, and export configurationโ€ permission, a permission that only trusted administrators should be given. Other measures in the product prevent the execution of PHP scripts, so another server-side scripting language must be accessible on the server to execute code.

0.001 Low

EPSS

Percentile

40.4%

Related for CVELIST:CVE-2019-19902