Impact
The vulnerability arises from Backpack‑CRUD’s color column template, which mistakenly renders raw content because the $column['escaped'] flag logic is inverted. The affected template is used in versions from 6.0.0 through 6.8.14 and 7.0.38. A malicious actor who can write into this column can embed JavaScript that will execute in any user’s browser that opens the CRUD list, including administrators. The flaw is limited to client‑side execution; it does not allow server‑side code execution or arbitrary file uploads, but it enables stealth attacks such as cookie theft or unauthorized actions within the application.
Affected Systems
Affected products are Laravel‑Backpack:CRUD, versions released between 6.0.0 and just before 6.8.14, and also all releases leading up to 7.0.38. Users running any version of Backpack‑CRUD older than 6.0.38 should be aware that the color column could render unescaped content.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity. The EPSS score of < 1% shows a very low but nonzero likelihood of exploitation under current conditions. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to have write access to the color page; once an untrusted script is stored, any user who opens the list will execute it, potentially compromising session data or performing actions on behalf of the victim within the application.
OpenCVE Enrichment
Github GHSA