Address Suggestion
An ordinary account on the site could see malicious code run in their browser if they searched for an address that returned a poisoned suggestion. This could allow an attacker to read private data or change content on the site.
- Who could do thisOnly someone with a login on your site.
- Does it apply to youA site is affected if an attacker can inject malicious content into the address provider and a user searches for that specific suggestion.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Address Suggestion to 1.0.25.
For developers: what the fix changed
The fix sanitises address suggestion data by escaping HTML entities in the `handleAutocomplete` method of `src/Controller/AddressSuggestion.php` and in `js/ckeditor5_plugins/addressSuggestion/src/InsertAddressCommand.js`. It also updates `js/address_suggestion.js` to use jQuery's `.text()` method instead of raw HTML concatenation when appending new options.
Also in this release The release also includes code style improvements, PHPCS/PHPStan fixes, and minor JavaScript refactoring.
js/address_suggestion.js+69 −42 fixjs/build/addressSuggestion.js+1 −1 fixjs/ckeditor5_plugins/addressSuggestion/src/AddressSuggestionIcon-view.js+1 −1js/ckeditor5_plugins/addressSuggestion/src/InsertAddressCommand.js+18 −2 fixsrc/Controller/AddressSuggestion.php+13 −5 fixsrc/Element/AddressSuggestion.php+5 −5src/Hook/AddressSuggestionHooks.php+74 −74src/Plugin/AddressProvider/BingMaps.php+2 −2src/Plugin/AddressProvider/CAPost.php+2 −2src/Plugin/AddressProvider/DistanceMatrix.php+2 −2src/Plugin/AddressProvider/FranceAddress.php+2 −2src/Plugin/AddressProvider/GoogleMaps.php+2 −2