Backdrop core - Critical - Remote Code Execution - SA-CORE-2019-003
Link fields do not properly sanitize data from non-form sources. This can lead to arbitrary PHP code execution in some cases.
Note: A site is only affected by this if the site has a web services module enabled (like Services module) or exposes another API that allows content creation.
- Backdrop Core 1.x versions prior to versions 1.12.2 and 1.11.5.
Versions of Backdrop CMS prior to 1.11.x do not receive security coverage.