Backdrop core - Less critical - Cross Site Scripting - BACKDROP-SA-CORE-2025-004
Backdrop core Link field attributes may not be sufficiently sanitized in specialized scenarios, which can lead to a Cross Site Scripting vulnerability (XSS).
This vulnerability is not directly exploitable within core itself, nor are there any contributed modules that appear to exhibit the behavior. This is a security hardening to prevent such attacks in the future. This problem has not been reproducible without a specialized module.
Sites are not affected if they are not extending the Link field module in ways that provide the ability to input additional link attributes.
- Backdrop Core 1.30.x versions prior to 1.30.2
- Backdrop Core 1.29.x versions prior to 1.29.5
Backdrop versions 1.28 and prior do not receive security coverage.