AT Internet SmartTag
A person with an administrator account could enter harmful scripts into text areas. These scripts would run when other visitors look at the affected pages. This would allow the attacker to read private details or alter website content.
- Who could do thisOnly someone with an administrator login.
- Does it apply to youThis applies if a user has the access right to manage the smart tag service.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate AT Internet SmartTag to 1.0.1.
For developers: what the fix changed
The release diff is linked below. No summary of the fix has been written for this one.
atsmarttag.permissions.yml+1 −0