GHSA-g8jw-8vpv-pv5q

Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/11/GHSA-g8jw-8vpv-pv5q/GHSA-g8jw-8vpv-pv5q.json
Aliases
  • CVE-2022-42096
Published
2022-11-21T21:30:14Z
Modified
2022-11-23T17:55:22.002817Z
Details

Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via Post content. The account must have admin privileges.

References

Affected packages

Packagist / backdrop/backdrop

backdrop/backdrop

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0
Last affected
1.23.0

Affected versions

1.*

1.13.2-rc1
1.13.2-rc2
1.17.3
1.18.3
1.19.1
1.20.3
1.21.0
1.21.1
1.21.3
1.21.4
1.22.1
1.22.2