Backdrop CMS before 1.28.4 and 1.29.x before 1.29.2 allows XSS via an SVG document, if the SVG tag is allowed for a text format.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://backdropcms.org/security/backdrop-sa-core-2024-002 |
|
History
Mon, 26 Jan 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Backdropcms
Backdropcms backdrop |
|
| CPEs | cpe:2.3:a:backdropcms:backdrop:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Backdropcms
Backdropcms backdrop |
Fri, 29 Nov 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Fri, 29 Nov 2024 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Backdrop CMS before 1.28.4 and 1.29.x before 1.29.2 allows XSS via an SVG document, if the SVG tag is allowed for a text format. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-11-29T18:31:00.244Z
Reserved: 2024-11-29T00:00:00
Link: CVE-2024-54123
Updated: 2024-11-29T18:30:53.260Z
Status : Analyzed
Published: 2024-11-29T04:15:03.940
Modified: 2026-01-26T15:51:32.997
Link: CVE-2024-54123
No data.
OpenCVE Enrichment
No data.