Geolocation Field
Anyone without logging in could enter malicious database commands into a map filter. They could view any private information on the website and modify any files including the underlying code.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youA site is affected if it has a list of content that uses the map filter and is set to accept user input.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this critical. Cyber Essentials expects a fix within 14 days. Do it this week.
Tell your developerUpdate Geolocation Field to 8.x-3.15.
For developers: what the fix changed
The fix updates the `ProximityFilter` views filter in `src/Plugin/views/filter/ProximityFilter.php` to use parameterised queries instead of concatenating user input directly into SQL expressions. It also casts boundary and proximity filter inputs to floats in `src/BoundaryTrait.php` and `src/ProximityTrait.php` to ensure they are safe.
Also in this release The release also addresses PHP 8.4 deprecations, adds MySQL 8.0+ SRID 4326 axis order handling, implements Google Places API session tokens, and updates tests.
config/schema/geolocation.views.schema.yml+4 −0modules/geolocation_address/geolocation_address.module+1 −1modules/geolocation_address/js/geolocation-address-map-widget.js+11 −5modules/geolocation_demo/config/install/core.base_field_override.node.geolocation_default_article.promote.yml+0 −0modules/geolocation_demo/config/install/core.entity_form_display.node.geolocation_default_article.default.yml+0 −0modules/geolocation_demo/config/install/core.entity_form_display.taxonomy_term.geolocation_demo_taxonomy.default.yml+0 −0modules/geolocation_demo/config/install/core.entity_view_display.node.geolocation_default_article.default.yml+0 −0modules/geolocation_demo/config/install/core.entity_view_display.node.geolocation_default_article.teaser.yml+0 −0modules/geolocation_demo/config/install/core.entity_view_display.taxonomy_term.geolocation_demo_taxonomy.default.yml+0 −0modules/geolocation_demo/config/install/field.field.node.geolocation_default_article.body.yml+0 −0modules/geolocation_demo/config/install/field.field.node.geolocation_default_article.field_geolocation_demo_multiple.yml+0 −0modules/geolocation_demo/config/install/field.field.node.geolocation_default_article.field_geolocation_demo_single.yml+0 −0