Editoria11y Accessibility Checker
An ordinary account on the site could edit or delete the accessibility checker data because an access right was set up incorrectly. They could remove important accessibility warnings. They could not read any restricted content.
- Who could do thisOnly someone with a login on your site.
- Does it apply to youAny site using this module.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Editoria11y Accessibility Checker to 2.2.23 or 3.0.9, whichever branch you are on.
For developers: what the fix changed
Updates the title and description of the 'view editoria11y checker' permission in editoria11y.permissions.yml to clarify its purpose and effect.
editoria11y.permissions.yml+2 −2 fix