Date: 
Thursday, Jun 29th, 2017
Advisory ID: 
BACKDROP-SA-CONTRIB-2017-007
Security risk: 
Critical
Vulnerability: 
SQL Injection
Versions affected: 
Description: 

The module doesn't sufficiently sanitize column names provided by the client when they are querying for data and trying to sort it.  

This vulnerability is mitigated by the fact that a site must have an "Index" resource enabled and the attacker must know the endpoint's URL.

Solution: 

If you use the Services module for Backdrop CMS 1.x, upgrade to services1.x-3.0.2-beta

Reported By: 
Fixed By: 
Coordinated By: 

Security email list

Backdrop maintains a security mailing list. Whenever a security release comes out, an email will be sent to everyone subscribed to that list, announcing the new release. Please follow the steps below to join the Security email list.

  1. Log in to backdropcms.org
  2. Edit your profile
  3. Switch to the "Subscriptions" tab
  4. Check the box labeled "Security updates"
  5. Save the form