Advanced Search
The module does not properly check access rights when block IDs are sent to its public address. A visitor could read restricted block content. They could not change any data.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youAny site using this module where a restricted block contains sensitive content and its ID is known or guessed.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Advanced Search to 2.4.5.
For developers: what the fix changed
The fix adds an access check for the view operation on the block entity in src/Controller/AjaxBlocksController.php before rendering it.
Also in this release Added a functional test to ensure block access is enforced.
src/Controller/AjaxBlocksController.php+1 −1 fix