Impact
An unauthenticated attacker can download configuration export archives that remain on the server, exposing the complete site configuration and sensitive data. The weakness is a classic Information Disclosure flaw (CWE‑200) that allows third parties to read confidential information without authenticating.
Affected Systems
Backdrop CMS versions earlier than 1.35.1 are affected. The vulnerability applies to all installations of the Backdrop CMS product for which configuration export archives are left accessible on the web server.
Risk and Exploitability
The vulnerability scores 8.2 on CVSS, indicating high severity. The EPSS score is not available, but the impact of exposing the entire configuration suggests that attackers could easily harvest this data without needing any credentials. The issue is not listed in the CISA KEV catalog. Attackers can exploit the flaw simply by accessing the export archive URL through a web browser or with a script, making the attack vector publicly reachable.
OpenCVE Enrichment