Diba carousel slider
An ordinary account on the site could add hidden scripts to the slide descriptions. They could read private user details and change the text on the page. They could not take over the entire website.
- Who could do thisOnly someone with a login on your site.
- Does it apply to youThis applies to sites that use a formatted text field for the slide description and have enabled the allow HTML description option.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Diba carousel slider to 3.0.2.
For developers: what the fix changed
The fix applies text format filtering or admin XSS filtering to the description in `src/Plugin/Block/DibaCarousel.php` when HTML is allowed, and removes the `|raw` filter from variables in `templates/block--diba-carousel.html.twig`.
Also in this release Updated GitLab CI configuration.
.gitlab-ci.yml+70 −36src/Plugin/Block/DibaCarousel.php+15 −2 fixtemplates/block--diba-carousel.html.twig+4 −4 fix