The Salesforce module before 1.x-1.0.1 for Backdrop CMS does not properly use a random state parameter to protect the authorization flow against CSRF attacks.
Metrics
Affected Vendors & Products
References
History
Tue, 12 May 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 12 May 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Backdropcms
Backdropcms backdrop-contrib/salesforce |
|
| Vendors & Products |
Backdropcms
Backdropcms backdrop-contrib/salesforce |
Tue, 12 May 2026 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Cross‑Site Request Forgery Vulnerability in Backdrop CMS Salesforce Module |
Tue, 12 May 2026 04:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Salesforce module before 1.x-1.0.1 for Backdrop CMS does not properly use a random state parameter to protect the authorization flow against CSRF attacks. | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-05-12T12:59:07.153Z
Reserved: 2026-05-12T04:06:23.682Z
Link: CVE-2026-45430
Updated: 2026-05-12T12:57:48.842Z
Status : Received
Published: 2026-05-12T04:16:28.027
Modified: 2026-05-12T04:16:28.027
Link: CVE-2026-45430
No data.