Google Analytics GA4
The system does not clean up custom attributes added to the tracking code. A person with the right to change these settings could add malicious scripts that run on every page. They could see private information and change data on the website.
- Who could do thisOnly someone with an administrator login.
- Does it apply to youThis applies when a person has the access right to configure the tracking settings.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Google Analytics GA4 to 1.1.14.
For developers: what the fix changed
The fix adds strict validation to the scripts_custom_attributes field in src/Form/Ga4GoogleAnalyticsSettings.php using a regex allowlist and filters the attributes in ga4_google_analytics_page_attachments within ga4_google_analytics.module to ensure only safe attributes are included.
ga4_google_analytics.module+15 −0 fixsrc/Form/Ga4GoogleAnalyticsSettings.php+51 −0 fix