Entity Browser
An administrator account could add malicious code to the titles of tabs. This code would run when other people view the tool. The attacker could then view hidden information or change data on the website.
- Who could do thisOnly someone with an administrator login.
- Does it apply to youThis applies to any site where an attacker can insert specific code on a page that shows the selection tool.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Entity Browser to 8.x-2.16.
For developers: what the fix changed
The fix sanitises the tab title by wrapping it in Drupal.checkPlain in the js/entity_browser.tabs.js file.
js/entity_browser.tabs.js+1 −1 fix