CVE detail
CVE-2019-14770 — CVE-2019-14770
Published 2019-08-08 · Modified 2026-06-17 · Vendor backdropcms · Product backdrop_core · Source nvd
MEDIUM
severity
CVSS-derived band
0.0079
EPSS probability
exploitation probability, 30d
53.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
In Backdrop CMS 1.12.x before 1.12.8 and 1.13.x before 1.13.3, some menu links within the administration bar may be crafted to execute JavaScript when the administrator is logged in and uses the search functionality. (This issue is mitigated by the attacker needing permissions to create administrative menu links, such as by creating a content type or layout. Such permissions are usually restricted to trusted or administrative users.)
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References