1 results (0.002 seconds)

CVSS: 4.8EPSS: 0%CPEs: 2EXPL: 0

Backdrop CMS before 1.27.3 and 1.28.x before 1.28.2 does not sufficiently sanitize field labels before they are displayed in certain places. This vulnerability is mitigated by the fact that an attacker must have a role with the "administer fields" permission. Backdrop CMS anterior a 1.27.3 y 1.28.x anterior a 1.28.2 no sanitiza suficientemente las etiquetas de campo antes de que se muestren en ciertos lugares. Esta vulnerabilidad se ve mitigada por el hecho de que un atacante debe tener un rol con permiso de "administer fields". • https://backdropcms.org/security/backdrop-sa-core-2024-001 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •