Flag - Moderately Critical - Cross Site Scripting - BACKDROP-SA-CONTRIB-2025-011
Project
Date
Severity
Moderately Critical
Affected versions
<7.x-3.10
The module doesn't verify flag links before performing the flag action, or verify that the response returned was provided by the flag module. This can allow specially crafted HTML to result in Cross Site Scripting.