S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Mar 5, 2024

CVE-2022-42095 Scanner

CVE-2022-42095 scanner - Cross Site Scripting (Stored) vulnerability in Backdrop CMS

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.8k
Times Used
continuous scan runs
5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-42095
4.8
CVSSmedium
Exploitable remotely over the internet · requires high privileges · user interaction needed.

Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Page content.

Attack Vector
Network
Privileges Req.
High
User Interaction
Required
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

Backdrop CMS, an open-source content management system, is designed for creating and managing websites with ease. It is used globally by businesses, non-profits, and individuals who seek a flexible and straightforward platform for their web presence. Version 1.23.0 of Backdrop CMS, while offering various features and improvements, was found to have a security flaw. This software facilitates the construction of diverse websites ranging from simple blogs to comprehensive business sites. It is favored for its user-friendly interface and extensive customization options.

The vulnerability detected in Backdrop CMS version 1.23.0 is a type of stored Cross-Site Scripting (XSS). This vulnerability allows attackers to inject malicious scripts into web pages, which are then executed in the browser of anyone who views those pages. As a stored XSS vulnerability, the malicious code is saved on the server and affects all users viewing the infected page. This poses a significant security risk, enabling attackers to steal data, hijack user sessions, or deface the website.

The stored XSS vulnerability in Backdrop CMS 1.23.0 specifically affects the Page content creation and editing function. Attackers can exploit this by crafting malicious input in the Page content fields, which is not properly sanitized before being stored and subsequently rendered to users. The vulnerability is triggered when a user views a page containing the malicious content, leading to the execution of arbitrary JavaScript code in the viewer's browser. This issue highlights the importance of input validation and output encoding in web applications.

The exploitation of this stored XSS vulnerability can have several harmful effects, including unauthorized access to user sessions, leading to account takeover; theft of sensitive information such as personal data and login credentials; and the potential for website defacement, damaging the integrity and reputation of the site. It also opens the door for further attacks against site users.

By leveraging the advanced security scanning capabilities of the S4E platform, users can identify and mitigate vulnerabilities like the stored XSS flaw in Backdrop CMS version 1.23.0. Our platform offers a comprehensive cyber threat exposure management service that helps protect digital assets against a wide range of security vulnerabilities. Joining our platform ensures you are equipped with the tools and knowledge to maintain a secure and resilient online presence, safeguarding your data and that of your users from potential cyber threats.

 

References

Solution Advice
  1. Immediately upgrade to the latest version of Backdrop CMS that addresses this XSS vulnerability.
  2. Implement rigorous input sanitization and validation measures to prevent the insertion of malicious scripts.
  3. Regularly review and update security configurations and practices to defend against new and emerging threats.
  4. Educate users and administrators about the risks of XSS attacks and encourage safe browsing practices.
  5. Perform regular security audits and penetration testing to identify and rectify potential security weaknesses.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.