Cross Site Scripting Vulnerability in Backdrop CMS Mail Disguise Module
CVE-2025-27823

6.4MEDIUM

Key Information:

Vendor
CVE Published:
7 March 2025

What is CVE-2025-27823?

A security issue has been identified in the Mail Disguise module for Backdrop CMS, which is designed to obfuscate email addresses and prevent spambots from collecting them. The vulnerability arises due to inadequate validation of data attribute values in link elements, potentially allowing attackers to execute Cross Site Scripting (XSS) attacks. Successful exploitation requires an attacker’s ability to insert malicious links with crafted data attributes into web pages. This poses a risk to the integrity and security of affected websites.

Affected Version(s)

Mail Disguise 0 < 1.x-1.0.5

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-27823 : Cross Site Scripting Vulnerability in Backdrop CMS Mail Disguise Module