- Backdrop Core versions prior to 1.9.2
Backdrop core has an external link injection vulnerability when the language switcher block is used. A similar vulnerability exists in various custom and contributed modules. This vulnerability could allow an attacker to trick users into unwillingly navigating to an external site.
Upgrade your site to the most recent version of Backdrop core. Download available on the Backdrop CMS 1.9.2 release page. See the update instructions, if needed.
- David Rothstein of the Drupal Security Team
- David Rothstein of the Drupal Security Team
- Samuel Mortenson
- Nate Lampton of the Backdrop Security Team
- Jess of the Drupal Security Team
- Michael Hess of the Drupal Security Team
- Nate Lampton of the Backdrop Security Team