vendor:
Backdrop CMS
by:
Ahmet Ümit BAYRAM
6.1
CVSS
HIGH
Remote Command Execution (RCE)
CWE
Product Name: Backdrop CMS
Affected Version From: 1.27.1
Affected Version To: 1.27.1
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: MacOS
2024
Backdrop CMS 1.27.1 – Remote Command Execution (RCE)
The exploit allows remote attackers to execute arbitrary commands on the target system by creating a malicious module in Backdrop CMS version 1.27.1.
Mitigation:
Update Backdrop CMS to the latest version available, avoid executing untrusted code, and regularly monitor for any suspicious activities.