Orejime
This module manages consent for embedded content.
A person with an ordinary account could add malicious scripts to a piece of content. These scripts would run when other people view the page. The person could use this to view or alter information that they should not be able to reach.
- Who could do thisOnly someone with a login on your site.
- Does it apply to youThis applies if the site has a text format enabled that allows iframe consent tags with alt attributes alongside the enable JS iframe consent option, and the person has an access right to create or edit content using that format.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Orejime to 2.0.16.
For developers: what the fix changed
The fix escapes the poster, title, and alt attributes using Drupal.checkPlain in the constructor of the IframeConsent element in js/orejime_iframe_consent.js.
js/orejime_iframe_consent.js+3 −3 fix