Calculation Fields
The system does not properly check the information typed into the form. A person could enter malicious scripts to see private information or change data on the website.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youAny site using this module.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Calculation Fields to 1.0.4.
For developers: what the fix changed
Adds HTML escaping to calculation results and enforces numeric validation on inputs in `js/calculation-fields.js` and `FormCalculationMarkupElement.php` to prevent XSS.
Also in this release Removed packaging metadata from info files, updated README documentation, and improved handling of zero values in expressions.
README.md+17 −2calculation_fields.info.yml+0 −6calculation_fields.module+1 −1js/calculation-fields.js+69 −13 fixmodules/calculation_fields_example/calculation_fields_example.info.yml+0 −5modules/calculation_fields_example/calculation_fields_example.module+1 −1modules/webform_calculation_fields/README.md+8 −3modules/webform_calculation_fields/modules/webform_calculation_fields_examples/webform_calculation_fields_examples.info.yml+0 −5modules/webform_calculation_fields/src/Plugin/WebformElement/WebformCalculationNumber.php+0 −1modules/webform_calculation_fields/webform_calculation_fields.info.yml+0 −5src/CalculationFieldsTrait.php+1 −2src/Element/FormCalculationElement.php+3 −5