Content Moderation Notifications
An administrator account could be given the access right to edit email templates without realising this grants deep access to the system. The user could then run malicious code within those templates to read highly sensitive information or change anything on the website.
- Who could do thisOnly someone with an administrator login.
- Does it apply to youAny site using this module.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Content Moderation Notifications to 8.x-3.9.
For developers: what the fix changed
Adds the restrict access flag to the administer content moderation notifications permission in content_moderation_notifications.permissions.yml.
content_moderation_notifications.permissions.yml+2 −1 fix