CSS Usage Analyzer
Anyone without logging in could send fake design measurements to the site. They could add false statistics to the administrator reports. They could not view any private information.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youAny site using this module.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate CSS Usage Analyzer to 1.0.2.
For developers: what the fix changed
The fix introduces a new permission in css_usage_analyzer.routing.yml to restrict access to the save endpoint. It also implements flood control and URL validation in the ajaxSave method of src/Controller/CssUsageAnalyzerController.php to prevent forged or repeated submissions.
Also in this release The release also adds an update hook and updates the README file to document the new permission.
README.md+15 −2css_usage_analyzer.install+7 −0css_usage_analyzer.module+1 −1 fixcss_usage_analyzer.permissions.yml+5 −0 fixcss_usage_analyzer.routing.yml+6 −3 fixsrc/Controller/CssUsageAnalyzerController.php+46 −0 fix