Backdrop core - Critical - Arbitrary PHP code execution - BACKDROP-SA-CORE-2020-008
Date: Wednesday, Nov 25th, 2020
Security risk: Critical
Advisory ID: BACKDROP-SA-CORE-2020-008
CVE ID: CVE-2020-28948, CVE-2020-28949
Vulnerability: Arbitrary PHP code execution
Versions affected
- Backdrop Core 1.17.x versions prior to 1.17.4
- Backdrop Core 1.16.x versions prior to 1.16.6
Backdrop versions 1.15 and prior do not receive security coverage.