VYPR
Moderate severityNVD Advisory· Published Jul 22, 2024· Updated Mar 21, 2025

CVE-2024-41709

CVE-2024-41709

Description

Backdrop CMS before 1.27.3 and 1.28.x before 1.28.2 does not sufficiently sanitize field labels before they are displayed in certain places. This vulnerability is mitigated by the fact that an attacker must have a role with the "administer fields" permission.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
backdrop/backdropPackagist
< 1.27.31.27.3
backdrop/backdropPackagist
>= 1.28.0, < 1.28.21.28.2

Affected products

2

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.