XSS Vulnerability in Backdrop CMS Versions Prior to 1.28.5 and 1.29.3
CVE-2025-25063

4.4MEDIUM

Key Information:

Status
Vendor
CVE Published:
3 February 2025

What is CVE-2025-25063?

An XSS vulnerability exists in Backdrop CMS versions 1.28.x prior to 1.28.5 and 1.29.x prior to 1.29.3, due to insufficient validation of uploaded SVG images. Attackers can potentially exploit this flaw by uploading specially crafted SVG files containing dangerous scripts. While exploitation requires the attacker to upload the SVG, and Backdrop CMS embeds these images in <img> tags which limits execution, any direct access to the SVG via its URL could lead to script execution in the browser. It is crucial for users to update their Backdrop CMS to the latest versions to mitigate this security risk.

Affected Version(s)

backdrop 1.28.0 < 1.28.5

backdrop 1.29.0 < 1.29.3

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.