Block AJAX
It provides the ability to load blocks of content asynchronously without reloading the page.
A visitor could send malicious data to the website to run dangerous code on the server. This could give them total control over the system. They could read or change absolutely everything on the website.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youA site is affected if it has the layout builder enabled or uses another block plugin that handles data in an unsafe way.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this highly critical. Cyber Essentials expects a fix within 14 days. Do it this week.
Tell your developerUpdate Block AJAX to 3.0.2.
For developers: what the fix changed
The fix modifies src/Controller/AjaxBlockController.php to retrieve block configuration directly from the stored block entity instead of accepting user supplied configuration and plugin IDs from the request. It also updates js/ajax_blocks.js to stop sending these parameters in the AJAX request.
Also in this release The release adds support for cacheable responses and includes various JavaScript and CSS code style updates.
.cspell-project-words.txt+3 −0README.md+30 −0block_ajax.routing.yml+0 −1css/ajax_blocks.css+10 −8js/ajax_blocks.js+81 −46 fixsrc/AjaxBlocks.php+1 −1src/BlockViewBuilder.php+1 −1src/Controller/AjaxBlockController.php+87 −100 fixsrc/Controller/AjaxBlockListController.php+1 −1src/Form/AjaxBlockForm.php+2 −0src/Response/AjaxBlockResponse.php+2 −3