An XSS issue was discovered in the Link iframe formatter module before 1.x-1.1.1 for Backdrop CMS. It doesn't sufficiently sanitize input before displaying results to the screen. This vulnerability is mitigated by the fact that an attacker must have the ability to create content containing an iFrame field.
History

Mon, 10 Mar 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 07 Mar 2025 22:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Fri, 07 Mar 2025 22:00:00 +0000

Type Values Removed Values Added
Description An XSS issue was discovered in the Link iframe formatter module before 1.x-1.1.1 for Backdrop CMS. It doesn't sufficiently sanitize input before displaying results to the screen. This vulnerability is mitigated by the fact that an attacker must have the ability to create content containing an iFrame field.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-03-07T00:00:00.000Z

Updated: 2025-03-07T22:30:26.688Z

Reserved: 2025-03-07T00:00:00.000Z

Link: CVE-2025-27824

cve-icon Vulnrichment

Updated: 2025-03-07T22:30:23.424Z

cve-icon NVD

Status : Received

Published: 2025-03-07T22:15:38.220

Modified: 2025-03-07T22:15:38.220

Link: CVE-2025-27824

cve-icon Redhat

No data.