- Navbar versions prior to 1.x-1.8.0
This module provides a very simple, mobile-friendly navigation toolbar.
The module doesn't sufficiently check for user-provided input.
This vulnerability is mitigated by the fact that an attacker must have the ability to post content using a text format (like the default "Filtered HTML" format) that won't filter out the exploit code.
Upgrade your site to the most recent version of the navbar module. Download available on the Navbar 1.x-1.8.0 release page.
- Ivo Van Geertruyen of the Drupal Security Team
- Attila Vasas for Backdrop CMS
- David Snopek of the Drupal Security Team
- Jen Lampton of the Backdrop CMS Security Team