Date iCal
A visitor without an account could view any private information on the website by looking at the calendar data feeds. They could read all hidden data on the site. They could not alter or delete any information.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youAny site using this module.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this critical. Cyber Essentials expects a fix within 14 days. Do it this week.
Tell your developerUpdate Date iCal to 4.0.15.
For developers: what the fix changed
The fix adds access checks for entities and fields to the feed method in src/Controller/DateIcalController.php and sanitises user input in the download method. It also strips HTML tags from the rrule field in src/DateICal.php.
Also in this release The release also fixes an issue with finding the frequency in raw RRULEs.
src/Controller/DateIcalController.php+65 −11 fixsrc/DateICal.php+1 −1 fix