AJAX Dashboard
This module lets developers build interactive control panels for different pieces of content.
The system does not check if a person has the right to view the settings page. Anyone visiting the site could turn the control panels on or off and see private information. They could not edit the actual layout of the panels.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youThis applies when the extra feature for attaching control panels to pieces of content is turned on.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this critical. Cyber Essentials expects a fix within 14 days. Do it this week.
Tell your developerUpdate AJAX Dashboard to 3.1.0.
For developers: what the fix changed
Changes the access requirement for the settings route in ajax_dashboard_entity_dashboard.routing.yml from a blanket true to requiring the administer ajax_dashboard_entity_dashboard permission.
Also in this release Fixed a typo in the module info file.
modules/ajax_dashboard_entity_dashboard/ajax_dashboard_entity_dashboard.info.yml+1 −1modules/ajax_dashboard_entity_dashboard/ajax_dashboard_entity_dashboard.routing.yml+1 −1 fix