Feed Block
The module does not properly clean up the external data feed before displaying it on the screen. A user with an ordinary account could insert harmful scripts into the feed that run when someone views the page to read private information and change some data.
- Who could do thisOnly someone with a login on your site.
- Does it apply to youAny site using this module.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Feed Block to 3.0.2 or 2.0.2, whichever branch you are on.
For developers: what the fix changed
The fix sanitises feed item URLs using `UrlHelper::stripDangerousProtocols()` and validates them with `UrlHelper::isValid()` in `RSSFeedFormatter.php`. It also changes the feed URL input field type from textfield to url in `RSSFeedWidget.php`.
Also in this release The release adds a security warning to the module help text and introduces a test module to mock feed requests.
src/Hook/FeedBlockHooks.php+2 −0src/Plugin/Field/FieldFormatter/RSSFeedFormatter.php+21 −11 fixsrc/Plugin/Field/FieldWidget/RSSFeedWidget.php+1 −1 fix