CVE-2019-19902
Last modified
CVE-2019-19902 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. An issue was discovered in Backdrop CMS 1.13.x before 1.13.5 and 1.14.x before 1.14.2. It allows the upload of entire-site configuration archives through the user interface or command line. EPSS estimates a 1.50% chance of exploitation in the next 30 days.
Description
An issue was discovered in Backdrop CMS 1.13.x before 1.13.5 and 1.14.x before 1.14.2. It allows the upload of entire-site configuration archives through the user interface or command line. It does not sufficiently check uploaded archives for invalid data, allowing non-configuration scripts to potentially be uploaded to the server. This issue is mitigated by the fact that the attacker would be required to have the "Synchronize, import, and export configuration" permission, a permission that only trusted administrators should be given. Other measures in the product prevent the execution of PHP scripts, so another server-side scripting language must be accessible on the server to execute code.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Backdropcms | Backdrop Cms | >= 1.13.0, < 1.13.5 |
| Backdropcms | Backdrop Cms | >= 1.14.0, < 1.14.2 |
References
- https://backdropcms.org/security/backdrop-sa-core-2019-016Vendor Advisory
- https://backdropcms.org/security/backdrop-sa-core-2019-016Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-19902?
How severe is CVE-2019-19902?
How do I fix CVE-2019-19902?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-19897In IXP EasyInstall 6.2.13723, there is Remote Code Execution…9.8
- CVE-2019-19898In IXP EasyInstall 6.2.13723, there are cleartext credential…7.5
- CVE-2019-19899Pebble Templates 3.1.2 allows attackers to bypass a protecti…9.8
- CVE-2019-1990In ihevcd_fmt_conv_420sp_to_420p of ihevcd_fmt_conv.c, there…
- CVE-2019-19900An issue was discovered in Backdrop CMS 1.13.x before 1.13.5…4.8
- CVE-2019-19901An issue was discovered in Backdrop CMS 1.13.x before 1.13.5…4.8
- CVE-2019-19903An issue was discovered in Backdrop CMS 1.14.x before 1.14.2…4.8
- CVE-2019-19905NetHack 3.6.x before 3.6.4 is prone to a buffer overflow vul…9.8
- CVE-2019-19906cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds writ…7.5
- CVE-2019-19907HrAddFBBlock in libfreebusy/freebusyutil.cpp in Kopano Group…9.8
- CVE-2019-19908phpMyChat-Plus 1.98 is vulnerable to reflected XSS via JavaS…6.1
- CVE-2019-19909An issue was discovered in Public Knowledge Project (PKP) pk…8.8
Are you affected by CVE-2019-19902?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
