Backdrop core - Moderately critical - Cross Site Scripting - SA-CORE-2019-008
Under certain circumstances the File module/subsystem allows a malicious user to upload a file that can trigger a cross-site scripting (XSS) vulnerability.
- Backdrop Core 1.12.x versions prior to 1.12.5
- Backdrop Core 1.11.x versions prior to 1.11.8