Component blocks
The module does not properly check user input before replacing text placeholders. A user with an ordinary account could read hidden data or change data.
- Who could do thisOnly someone with a login on your site.
- Does it apply to youAny site using this module where an attacker has an access right to edit layouts.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Component blocks to 1.2.7.
For developers: what the fix changed
The fix applies Xss::filterAdmin to the value before token replacement in the ComponentBlock class.
src/Plugin/Block/ComponentBlock.php+2 −1 fix