Anti-Spam by CleanTalk
An administrator could place malicious code on the page if they can alter the response from the spam protection service. They could use this to view private information or change content on the website. They could not take full control of the website.
- Who could do thisOnly someone with an administrator login.
- Does it apply to youThis applies if someone can alter the response from the spam protection service through a compromised server or a man in the middle attack.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Anti-Spam by CleanTalk to 9.7.1.
For developers: what the fix changed
The fix sanitises the API response message by passing it through `_cleantalk_filter_response()` in `_cleantalk_die()` and `ct_die()` within `src/CleantalkFuncs.php`, which now uses a custom HTML sanitisation method `apbct_sanitize_custom_message()`.
Also in this release Updated the bot detector wrapper URL and added a new DTO class in the common library.
cleantalk.libraries.yml+1 −1lib/Cleantalk/Common/Templates/Dto.php+59 −0src/CleantalkFuncs.php+78 −2 fixsrc/EventSubscriber/RequestSubscriber.php+2 −3 fix