AI CKEditor
An ordinary account on the site could use special template commands to extract confidential system data. They could view secret server details. They could not modify any content or settings.
- Who could do thisOnly someone with a login on your site.
- Does it apply to youAny site using this module.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate AI CKEditor to 1.4.3.
For developers: what the fix changed
The fix prevents Twig template injection by rendering the Twig template before replacing placeholders with user input in the `Tone` and `Translate` plugins.
Also in this release The release also adds cleanup logic for CKEditor settings when the module is uninstalled, along with a warning on the uninstall confirmation form.
ai_ckeditor.install+37 −0ai_ckeditor.module+10 −0ai_ckeditor.services.yml+3 −0package-lock.json+2 −2package.json+1 −1src/Hook/AiCKEditorHooks.php+81 −0src/Plugin/AiCKEditor/Tone.php+9 −6 fixsrc/Plugin/AiCKEditor/Translate.php+8 −6 fix