- Backdrop Core 1.16.x versions prior to 1.16.1
- Backdrop Core 1.15.x versions prior to 1.15.3
Backdrop versions 1.14 and prior do not receive security coverage.
Backdrop CMS has an Open Redirect vulnerability. For example, a user could be tricked into visiting a specially crafted link which would redirect them to an arbitrary external URL.
The vulnerability is caused by insufficient validation of the destination
query parameter in the backdrop_goto()
function.
Upgrade your site to the most recent version of Backdrop core. Download available on the Backdrop CMS 1.16.1 release page. See the update instructions, if needed.
- Drew Webber of the Drupal Security Team
- Fabian Franz
- David Snopek of the Drupal Security Team
- vortfu
- Jen Lampton of the Backdrop CMS Security Team
- Jen Lampton of the Backdrop CMS Security Team