- Backdrop Core 1.17.x versions prior to 1.17.1
- Backdrop Core 1.16.x versions prior to 1.16.4
Backdrop versions 1.15 and prior do not receive security coverage.
Backdrop core's built-in CKEditor image caption functionality is vulnerable to XSS.
This SA is equivalent to Drupal core - Moderately critical - Cross-site scripting - SA-CORE-2020-010
Upgrade your site to the most recent version of Backdrop core. Download available on the Backdrop CMS 1.17.1 release page. See the update instructions, if needed.
- Samuel Mortenson of the Drupal Security Team
- Wim Leers
- Henrik Danielsson
- Dor Tumarkin
- Jess of the Drupal Security Team
- Krzysztof Krzton
- Lee Rowlands of the Drupal Security Team