Cross Site Scripting Vulnerability in Backdrop CMS Mail Disguise Module
CVE-2025-27823
6.4MEDIUM
What is CVE-2025-27823?
A security issue has been identified in the Mail Disguise module for Backdrop CMS, which is designed to obfuscate email addresses and prevent spambots from collecting them. The vulnerability arises due to inadequate validation of data attribute values in link elements, potentially allowing attackers to execute Cross Site Scripting (XSS) attacks. Successful exploitation requires an attacker’s ability to insert malicious links with crafted data attributes into web pages. This poses a risk to the integrity and security of affected websites.
Affected Version(s)
Mail Disguise 0 < 1.x-1.0.5