First published: Thu Dec 20 2018(Updated: )
Backdrop CMS version 1.11.0 and earlier contains a Cross Site Scripting (XSS) vulnerability in Sanitization of custom class names used on blocks and layouts. that can result in Execution of JavaScript from an unexpected source.. This attack appear to be exploitable via A user must be directed to an affected page while logged in.. This vulnerability appears to have been fixed in 1.11.1 and later.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Backdrop CMS | <=1.11.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-1000813 is rated as medium with a severity value of 4.8.
CVE-2018-1000813 is a Cross Site Scripting (XSS) vulnerability in the Sanitization of custom class names used on blocks and layouts in Backdrop CMS version 1.11.0 and earlier.
CVE-2018-1000813 can be exploited by directing a user to a specially crafted URL that triggers the execution of JavaScript from an unexpected source.
To fix CVE-2018-1000813, update your Backdrop CMS installation to version 1.11.1 or apply the relevant patch provided by Backdrop CMS.
You can find more information about CVE-2018-1000813 at the following link: [https://backdropcms.org/security/backdrop-sa-core-2018-005](https://backdropcms.org/security/backdrop-sa-core-2018-005)