Medium severity6.1NVD Advisory· Published Aug 8, 2019· Updated Jun 17, 2026
CVE-2018-20962
CVE-2018-20962
Description
The Backpack\CRUD Backpack component before 3.4.9 for Laravel allows XSS via the select field type.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
backpack/crudPackagist | < 3.4.9 | 3.4.9 |
Affected products
3- Backpack\CRUD/Backpackdescription
- cpe:2.3:a:backpackforlaravel:backpack\\crud:*:*:*:*:*:*:*:*Range: <3.4.9
Patches
Vulnerability mechanics
References
7- github.com/Laravel-Backpack/CRUD/commit/8b6bd0a2d489a4690f6b1d7ace67e2f07f5f0cc6nvdPatchThird Party AdvisoryWEB
- github.com/Laravel-Backpack/CRUD/compare/3.4.8...3.4.9nvdPatchThird Party AdvisoryWEB
- github.com/Laravel-Backpack/CRUD/issues/1297nvdExploitIssue TrackingThird Party AdvisoryWEB
- github.com/Laravel-Backpack/CRUD/blob/master/CHANGELOG.mdnvdRelease NotesThird Party Advisory
- github.com/advisories/GHSA-6gfm-gpr3-8wh9ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2018-20962ghsaADVISORY
- github.com/Laravel-Backpack/CRUD/blob/8b6bd0a2d489a4690f6b1d7ace67e2f07f5f0cc6/CHANGELOG.mdghsaWEB
News mentions
0No linked articles in our index yet.