Commerce Core
This module provides online shopping features for a website.
A visitor could place malicious code into the comments section of an order receipt email. They could use this to view private information or alter content when the email is read. They could not take full control of the website.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youThis applies if the website uses the checkout feature and has the customer comments section turned on.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Commerce Core to 3.3.6.
For developers: what the fix changed
The fix removes the raw filter from the customer comments output in the commerce order receipt Twig template and replaces it with the nl2br filter to ensure the output is properly escaped.
modules/order/templates/commerce-order-receipt.html.twig+1 −1 fix