AI SEO/GEO Analyzer
An ordinary account on the site could trick the artificial intelligence into returning malicious code. This code would run when a user with higher access rights views the report. The attacker could read some restricted data and change or add some data.
- Who could do thisOnly someone with a login on your site.
- Does it apply to youThis applies if an attacker can add text to the content sent to the artificial intelligence tool.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate AI SEO/GEO Analyzer to 1.1.3.
For developers: what the fix changed
The fix introduces a convertMarkdownToSafeHtml method in src/AiSeoAnalyzer.php to strip unsafe HTML and links during Markdown conversion, and applies Xss::filterAdmin to the result. It also updates src/ReportService.php to pass stored report HTML through Xss::filterAdmin before rendering, and updates src/Controller/StreamAnalysisController.php to use the new sanitisation method.
src/AiSeoAnalyzer.php+31 −3 fixsrc/Controller/StreamAnalysisController.php+2 −3 fixsrc/ReportService.php+14 −6 fix