- Backdrop Core 1.35.x versions prior to 1.35.1
Backdrop versions 1.33 and prior do not receive security coverage. Note that the 1.34.x branch also did not receive this update because of significant CKEditor version discrepancies between 1.34.x and 1.35.x, and CKEditor does not provide security updates to previous versions. As such this update was only applied to 1.35.1.
The Backdrop project uses the CKEditor library for rich-text editing. CKEditor has released a security update that impacts Backdrop CMS.
Vulnerabilities are possible if Backdrop is configured to use CKEditor for rich-text editing. An attacker that can create or edit content (even without access to CKEditor themselves) may be able to exploit this Cross-Site Scripting (XSS) vulnerability to target other people with access to the rich-text CKEditor, including site admins with privileged access.
For more information, see CKEditor's security advisory:
Instructions for contributed modules
Some contributed projects may use additional CKEditor plugins that are not packaged in Backdrop core. People should review their own sites if they use one of these projects. CKEditor has also released another CVE that does not affect Backdrop, but may affect custom plugins or other use cases:
Upgrade your site to the most recent version of Backdrop core. Download available on the Backdrop CMS 1.35.1 release page. See the update instructions.
- indigoxela
- Nate Lampton of the Backdrop CMS Security Team
- catch (catch) of the Drupal Security Team
- Lee Rowlands (larowlan) of the Drupal Security Team
- Mohit Aghera (mohit_aghera), provisional member of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team
- Bram Driesen (bramdriesen) of the Drupal Security Team
- catch (catch) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Lee Rowlands (larowlan) of the Drupal Security Team
- Dave Long (longwave) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team