Backdrop core - Moderately Critical - Multiple Vulnerabilities - SA-CORE-2017-009
- Cross Site Scripting
- Access bypass
Access Bypass - Moderately Critical
When creating a view, you can optionally use Ajax to update the displayed data via filter parameters. The views subsystem/module did not restrict access to the Ajax endpoint to only views configured to use Ajax. This is mitigated if you have access restrictions on the view, however, many widely used contrib modules don't have access restrictions set on the default views they provide. Any view that does not have access controls on the default (master) display may be vulnerable. The vulnerability does not require any authentication to be exploited. A successful exploit results in some non-public data being made public.
Sites running versions of Backdrop prior to 1.x-1.7.2 should update immediately.
It is best practice to always include some form of access restrictions on all views, even if you are using another module to display them.
- Backdrop Core 1.x.x versions prior to 1.7.2