CVE-2022-42095 describes a stored cross-site scripting (XSS) vulnerability in Backdrop CMS version 1.23.0, allowing an authenticated attacker to inject malicious scripts into page content. This vulnerability has a CVSS score of 4.8 (Medium), indicating a network-based attack requiring high privileges and user interaction, with potential for low impact on confidentiality and integrity. While not listed on CISA's KEV catalog, a Nuclei template exists for detection, and its EPSS score suggests a higher-than-average exploitability probability compared to most CVEs. There is currently no evidence of active exploitation, Metasploit modules, or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.23.0CPE matchmatch criteria | cpe:2.3:a:backdropcms:backdrop_cms:1.23.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.