First published: Mon Feb 03 2025(Updated: )
An XSS issue was discovered in Backdrop CMS 1.28.x before 1.28.5 and 1.29.x before 1.29.3. It doesn't sufficiently isolate long text content when the CKEditor 5 rich text editor is used. This allows a potential attacker to craft specialized HTML and JavaScript that may be executed when an administrator attempts to edit a piece of content. This vulnerability is mitigated by the fact that an attacker must have the ability to create long text content (such as through the node or comment forms) and an administrator must edit (not view) the content that contains the malicious content. This problem only exists when using the CKEditor 5 module.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Backdrop CMS | <1.28.5 | |
Backdrop CMS | <1.29.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-25062 is considered a high severity vulnerability due to its potential for allowing cross-site scripting (XSS) attacks.
To fix CVE-2025-25062, you should update Backdrop CMS to the latest version, specifically to 1.28.5 or 1.29.3 and above.
Backdrop CMS versions 1.28.x before 1.28.5 and 1.29.x before 1.29.3 are affected by CVE-2025-25062.
CVE-2025-25062 allows attackers to exploit XSS vulnerabilities by injecting malicious HTML and JavaScript into long text content.
Any users running the affected versions of Backdrop CMS may be at risk from CVE-2025-25062 if they use the CKEditor 5 rich text editor.