2025-03-16 03:03:50 +00:00

60 lines
2.0 KiB
JSON

{
"id": "CVE-2025-27824",
"sourceIdentifier": "cve@mitre.org",
"published": "2025-03-07T22:15:38.220",
"lastModified": "2025-03-07T22:15:38.220",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "An XSS issue was discovered in the Link iframe formatter module before 1.x-1.1.1 for Backdrop CMS. It doesn't sufficiently sanitize input before displaying results to the screen. This vulnerability is mitigated by the fact that an attacker must have the ability to create content containing an iFrame field."
},
{
"lang": "es",
"value": "Se descubri\u00f3 un problema de XSS en el m\u00f3dulo formateador de iframe de enlaces anterior a la versi\u00f3n 1.x-1.1.1 para Background CMS. No depura lo suficiente la entrada antes de mostrar los resultados en la pantalla. Esta vulnerabilidad se mitiga por el hecho de que un atacante debe tener la capacidad de crear contenido que contenga un campo iFrame."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "cve@mitre.org",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N",
"baseScore": 6.4,
"baseSeverity": "MEDIUM",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "CHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"availabilityImpact": "NONE"
},
"exploitabilityScore": 3.1,
"impactScore": 2.7
}
]
},
"weaknesses": [
{
"source": "cve@mitre.org",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"references": [
{
"url": "https://backdropcms.org/security/backdrop-sa-contrib-2025-003",
"source": "cve@mitre.org"
}
]
}