Backdrop core - Moderately critical - Third-party library - BACKDROP-SA-CORE-2020-001
The Backdrop project uses the third-party library CKEditor, which has released a security improvement that is needed to protect some Backdrop configurations.
Vulnerabilities are possible if Backdrop is configured to use the Rich-Text editor, CKEditor, for editing content. When multiple people can edit content, the vulnerability can be used to execute XSS attacks against other people, including site admins with more access.
The latest versions of Backdrop update CKEditor to 4.14 to mitigate the vulnerabilities.
- Backdrop Core 1.15.x versions prior to 1.15.1
- Backdrop Core 1.14.x versions prior to 1.14.4
Backdrop versions 1.13 and prior do not receive security coverage.