Flag attendance field
An ordinary account on the site could write malicious data directly into an attendance field. This could allow them to view or alter any information on the site including the underlying code.
- Who could do thisOnly someone with a login on your site.
- Does it apply to youA site is affected if a person has access rights to edit a piece of content with an attendance field and the site allows full edit access through a data feed or another direct method.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this critical. Cyber Essentials expects a fix within 14 days. Do it this week.
Tell your developerUpdate Flag attendance field to 8.x-1.2.
For developers: what the fix changed
The fix prevents PHP object injection by passing an array with allowed_classes set to false as the second argument to unserialize in FlagAttendanceFormatter.php and FlagAttendanceWidget.php.
src/Plugin/Field/FieldFormatter/FlagAttendanceFormatter.php+1 −1 fixsrc/Plugin/Field/FieldWidget/FlagAttendanceWidget.php+1 −1 fix