Drupal AlternativeCommerce (Basket)
A person without an account could send specific data to the website to run their own computer code. This would let them view any private information stored on the site. They could also alter any content or change the underlying software itself.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youThis applies if a specific chain of code exists in the website software or its additions.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this highly critical. Cyber Essentials expects a fix within 14 days. Do it this week.
Tell your developerUpdate Drupal AlternativeCommerce (Basket) to 2.1.17.
For developers: what the fix changed
Replaces `serialize()` and `unserialize()` with `json_encode()` and `json_decode()` for `payInfo` in `src/BasketOrderForm.php` and `src/Controller/Pages.php`, adding a fallback to a safe `unserialize()` with `allowed_classes` set to `FALSE` for legacy data.
Also in this release Added CSRF token validation for API actions, hardened payment callback order finalization, and fixed negative values in basket count calculation.
basket.libraries.yml+1 −0basket.module+4 −0misc/basket.js+6 −2src/BasketOrderForm.php+11 −11 fixsrc/Controller/Pages.php+50 −3 fixsrc/Query/BasketQuery.php+1 −1