GHSA-rcrw-452r-xvqvHighCVSS 7.8
Backdrop CMS 1.34 before 1.34.5 and 1.35 before 1.35.1 doesn't sufficiently protect configuration...
🔗 CVE IDs covered (1)
📋 Description
Backdrop CMS 1.34 before 1.34.5 and 1.35 before 1.35.1 doesn't sufficiently protect configuration exports when delivering a compressed archive. This vulnerability is mitigated by the fact that an export must have been previously requested by someone with the "Synchronize, import, and export configuration" permission.
🔗 References (5)
- https://nvd.nist.gov/vuln/detail/CVE-2026-107914
- https://backdropcms.org/security/backdrop-sa-core-2026-006
- https://github.com/backdrop/backdrop/commit/1ae67061d9d487bb6cb3b8611191354052f34749
- https://github.com/backdrop/backdrop/commit/347c8e558254633205f431ce5c12321a7ae9248e
- https://github.com/advisories/GHSA-rcrw-452r-xvqv