Advanced Filesystem
It turns the file storage of a website into a manageable and observable system.
A malicious website could trick a logged in visitor into making unwanted changes. Someone could trigger a system backup or alter some data. They could not see any hidden information.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youA site is affected if the advanced filesystem backup feature is enabled.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Advanced Filesystem to 1.0.28.
For developers: what the fix changed
The fix adds a CSRF token requirement to multiple administrative route definitions within the advanced filesystem backup routing configuration.
modules/advanced_filesystem_backup/advanced_filesystem_backup.routing.yml+6 −0 fix