vendor:
Backdrop
by:
Ahmet Ümit BAYRAM
6.1
CVSS
HIGH
Remote Command Execution (RCE)
78
CWE
Product Name: Backdrop
Affected Version From: 1.27.1
Affected Version To: 1.27.1
Patch Exists: YES
Related CWE:
CPE: a:backdrop_cms:backdrop:1.27.1
Platforms Tested: MacOS
2024
Backdrop CMS 1.27.1 – Authenticated Remote Command Execution (RCE)
The Backdrop CMS version 1.27.1 is vulnerable to authenticated remote command execution. An attacker can exploit this vulnerability to execute arbitrary commands on the target system. This could lead to unauthorized access, data theft, and further compromise of the system. This exploit was authored by Ahmet Ümit BAYRAM.
Mitigation:
To mitigate this vulnerability, it is recommended to update Backdrop CMS to a non-vulnerable version. Additionally, restrict access to sensitive system functionalities and directories. Regular security assessments and monitoring can also help in detecting and preventing such exploits.