CVE-2018-1000813: XSS
Backdrop CMS version 1.11.0 and earlier contains a Cross Site Scripting (XSS) vulnerability in Sanitization of custom class names used on blocks and layouts. that can result in Execution of JavaScript from an unexpected source.. This attack appear to be exploitable via A user must be directed to an affected page while logged in.. This vulnerability appears to have been fixed in 1.11.1 and later.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-1000813?
The severity of CVE-2018-1000813 is rated as medium with a severity value of 4.8.
What is CVE-2018-1000813?
CVE-2018-1000813 is a Cross Site Scripting (XSS) vulnerability in the Sanitization of custom class names used on blocks and layouts in Backdrop CMS version 1.11.0 and earlier.
How can CVE-2018-1000813 be exploited?
CVE-2018-1000813 can be exploited by directing a user to a specially crafted URL that triggers the execution of JavaScript from an unexpected source.
How can I fix CVE-2018-1000813?
To fix CVE-2018-1000813, update your Backdrop CMS installation to version 1.11.1 or apply the relevant patch provided by Backdrop CMS.
Where can I find more information about CVE-2018-1000813?
You can find more information about CVE-2018-1000813 at the following link: [https://backdropcms.org/security/backdrop-sa-core-2018-005](https://backdropcms.org/security/backdrop-sa-core-2018-005)