Bootstrap Lite - Moderately critical - Cross Site Scripting - BACKDROP-SA-CONTRIB-2025-005

Date: 
Feb 19th, 2025
Security risk: 
Moderately Critical
Vulnerability: 
Cross Site Scripting

The Bootstrap Lite Backdrop CMS theme doesn't sufficiently sanitize certain class names.

A CVE has been requested, and this page will be updated as soon as an official number has been issued.

Advisory ID: 
BACKDROP-SA-CORE-2025-005
Versions affected: 
  • Bootstrap Lite module, 1.x versions prior to 1.x-1.4.5.

 

Bootstrap 5 Lite - Moderately critical - Cross Site Scripting - BACKDROP-SA-CONTRIB-2025-004

Date: 
Feb 19th, 2025
Security risk: 
Moderately Critical
Vulnerability: 
Cross Site Scripting

The Bootstrap 5 Lite Backdrop CMS theme doesn't sufficiently sanitize certain class names.

A CVE has been requested, and this page will be updated as soon as an official number has been issued.

Advisory ID: 
BACKDROP-SA-CONTRIB-2025-004
Versions affected: 
  • Bootstrap 5 Lite module, 1.x versions prior to 1.x-1.0.3.

 

Link iframe formatter - Moderately critical - Cross Site Scripting - BACKDROP-SA-CONTRIB-2025-003

Date: 
Feb 19th, 2025
Security risk: 
Moderately Critical
Vulnerability: 
Cross Site Scripting

The Link iframe formatter module doesn't sufficiently sanitize user input before displaying results to the screen.

This vulnerability is mitigated by the fact that an attacker must have the ability to create content containing an iFrame field.

A CVE has been requested, and this page will be updated as soon as an official number has been issued.

Advisory ID: 
BACKDROP-SA-CONTRIB-2025-003
Versions affected: 
  • Link iframe formatter module, 1.x versions prior to 1.x-1.1.1

GDPR cookies - Less critical - Cross Site Scripting - BACKDROP-SA-CONTRIB-2025-002

Date: 
Feb 12th, 2025
Security risk: 
Less Critical
Vulnerability: 
Cross Site Scripting

The GDPR cookies module contains a library with known vulnerabilities:

tarteaucitronjs is a package that provides compliance to the European cookie law.  Affected versions of this package are vulnerable to Cross-site Scripting (XSS) due to missing sanitization of the services attributes value, and improper user-input sanitization, via width, theme, controls, img and other attributes.

Advisory ID: 
BACKDROP-SA-CONTRIB-2025-002
Versions affected: 
  • GDPR cookies module, 1.x versions prior to 1.x-1.3.3.

 

Google Tag - Moderately critical - Cross Site Scripting - BACKDROP-SA-CONTRIB-2025-001

Date: 
Feb 6th, 2025
Security risk: 
Moderately Critical
Vulnerability: 
Cross Site Scripting

This module enables you to integrate the site with the Google Tag Manager (GTM) application.

The module doesn't have the "restrict access" flag on the "administer google_tag_container" permission. A user with this permission can load a GTM container that completely changes the page or inserts malicious JS, resulting in a cross site scripting vulnerability.

This vulnerability is mitigated by the fact that an attacker must have a role with the aforementioned permission.

Advisory ID: 
BACKDROP-SA-CONTRIB-2025-001
Versions affected: 
  • Google Tag module 1.x-1.x versions prior to 1.x-1.6.2.

Backdrop core - Moderately Critical - SVG Cross Site Scripting - BACKDROP-SA-CORE-2025-002

Date: 
Jan 8th, 2025
Security risk: 
Moderately Critical
Vulnerability: 
Cross Site Scripting

Backdrop CMS does not sufficiently validate uploaded SVG images to ensure they do not contain potentially dangerous SVG tags. SVG images can contain clickable links and executable scripting, and using a crafted SVG, it is possible to execute scripting in the browser when an SVG image is viewed.

This issue is mitigated by the attacker needing to be able to upload SVG images, and that Backdrop embeds all uploaded SVG images within <img> tags, which prevents scripting from executing. The SVG must be viewed directly by its URL in order to run any embedded scripting.

A CVE has been requested, and this page will be updated as soon as an official number has been issued.

Advisory ID: 
BACKDROP-SA-CORE-2025-002
Versions affected: 
  • Backdrop Core 1.29.x versions prior to 1.29.3
  • Backdrop Core 1.28.x versions prior to 1.28.5

Backdrop versions 1.27 and prior do not receive security coverage.

Backdrop core - Moderately Critical - CKEditor 5 Cross Site Scripting - BACKDROP-SA-CORE-2025-001

Date: 
Jan 8th, 2025
Security risk: 
Moderately Critical
Vulnerability: 
Cross Site Scripting

Backdrop CMS doesn't sufficiently isolate long text content when the CKEditor 5 rich text editor is used. This allows a potential attacker to craft specialized HTML and JavaScript that may be executed when an administrator attempts to edit a piece of content.

This vulnerability is mitigated by the fact that an attacker must have the ability to create long text content (such as through the node or comment forms) and an administrator must edit (not view) the content that contains the malicious content. This problem only exists when using the CKEditor 5 module.

A CVE has been requested, and this page will be updated as soon as an official number has been issued.

Advisory ID: 
BACKDROP-SA-CORE-2025-001
Versions affected: 
  • Backdrop Core 1.29.x versions prior to 1.29.3
  • Backdrop Core 1.28.x versions prior to 1.28.5

Backdrop versions 1.27 and prior do not receive security coverage.

Backdrop Core - Moderately critical - Multiple vulnerabilities - BACKDROP-SA-CORE-2024-003

Date: 
Nov 20th, 2024
Security risk: 
Moderately Critical
Vulnerability: 
Multiple vulnerabilities

Backdrop core contains a potential PHP Object Injection vulnerability that, if combined with another exploit, could lead to Remote Code Execution.

This issue is mitigated by the fact that in order to be exploitable, a separate vulnerability must be present that allows an attacker to pass unsafe input to unserialize(). There are no such known exploits in Backdrop core.

As part of the protection against this potential vulnerability, additional checks have been added to some of Backdrop core's database related code.

Advisory ID: 
BACKDROP-SA-CORE-2024-003
Versions affected: 
  • Backdrop Core 1.29.x versions prior to 1.29.2
  • Backdrop Core 1.28.x versions prior to 1.28.4

Backdrop versions 1.27 and prior do not receive security coverage.

Backdrop core - Critical - Cross Site Scripting - BACKDROP-SA-CORE-2024-002

Date: 
Nov 20th, 2024
Security risk: 
Critical
Vulnerability: 
Cross Site Scripting

Backdrop CMS doesn't sufficiently sanitize SVG images when they are embedded into content.

This vulnerability is mitigated by the fact that the SVG tag must be in the list of allowed tags for a text format, and an attacker must have a role with sufficient permission to access the format, and upload images. 

Advisory ID: 
BACKDROP-SA-CORE-2024-002
Versions affected: 
  • Backdrop Core 1.29.x versions prior to 1.29.2
  • Backdrop Core 1.28.x versions prior to 1.28.4

Backdrop versions 1.27 and prior do not receive security coverage.

Two-factor Authentication (TFA) - Critical - Access bypass - BACKDROP-SA-CONTRIB-2024-005

Date: 
Oct 2nd, 2024
Security risk: 
Critical
Vulnerability: 
Access bypass

This module enables you to allow and/or require users to use a second authentication method in addition to password authentication.

The module does not sufficiently migrate sessions before prompting for a second factor token.

This vulnerability is mitigated by the fact that an attacker must fixate a session on a victim system that is then authenticated with username and password without completing Two Factor authentication. An attacker must gather additional information regarding the entry form after authentication. An attacker must still present a valid token to complete authentication.

Advisory ID: 
BACKDROP-SA-CONTRIB-2024-005
Versions affected: 

Pages