Advanced Content Feedback (aka admin_feedback)
2 security fixes in one update. Advanced Content Feedback (aka admin_feedback) fixed 2 separate security bugs this week: 1 access bypass / insecure direct object reference (idor), 1 cross site scripting. One update covers all of them. The most serious, SA-CONTRIB-2026-052, is explained here and the full list is at the end of the card.
An ordinary account on the site could bypass access checks when submitting a comment to alter another feedback record. They could modify other visitor feedback submissions on the website but they could not view any hidden information.
- Who could do thisOnly someone with a login on your site.
- Does it apply to youA site is affected if an attacker has a role with the access right to give feedback.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Advanced Content Feedback (aka admin_feedback) to 8.x-2.8.
For developers: what the fix changed
The fix replaces the base64-encoded feedback ID with an HMAC-signed token in `AdminFeedbackController::insertFeedback()` and verifies this signature in `AdminFeedbackController::updateFeedback()` to prevent users from modifying arbitrary feedback records. It also updates `AdminFeedbackAjaxForm` to handle the validation result and ensures that a comment can only be set once per feedback record.
Also in this release Added flood control for vote submissions, batch processing for CSV exports, a feature to delete all feedback for a specific node, and made JavaScript markup themeable.
README.md+55 −0admin_feedback.install+25 −0admin_feedback.libraries.yml+1 −1admin_feedback.module+1 −0admin_feedback.permissions.yml+4 −0admin_feedback.routing.yml+17 −0config/install/admin_feedback.settings.yml+7 −3config/schema/admin_feedback.schema.yml+14 −0css/admin_feedback.css+1 −1js/admin_feedback.js+152 −98logo.png+0 −0src/Controller/AdminFeedbackController.php+277 −63 fix
- Moderately critical · Access bypass / Insecure Direct Object Reference (IDOR) · SA-CONTRIB-2026-052
- Moderately critical · Cross site scripting · SA-CONTRIB-2026-051