Lucene search

K
osvGoogleOSV:CVE-2019-19902
HistoryDec 19, 2019 - 6:15 a.m.

CVE-2019-19902

2019-12-1906:15:11
Google
osv.dev
12

AI Score

6.9

Confidence

High

EPSS

0.001

Percentile

40.4%

An issue was discovered in Backdrop CMS 1.13.x before 1.13.5 and 1.14.x before 1.14.2. It allows the upload of entire-site configuration archives through the user interface or command line. It does not sufficiently check uploaded archives for invalid data, allowing non-configuration scripts to potentially be uploaded to the server. This issue is mitigated by the fact that the attacker would be required to have the โ€œSynchronize, import, and export configurationโ€ permission, a permission that only trusted administrators should be given. Other measures in the product prevent the execution of PHP scripts, so another server-side scripting language must be accessible on the server to execute code.

AI Score

6.9

Confidence

High

EPSS

0.001

Percentile

40.4%

Related for OSV:CVE-2019-19902