Translate Drupal with GTranslate
An administrator could change the language links so that they send visitors to a different website. They could alter these links to point elsewhere. They could not view any private information.
- Who could do thisOnly someone with an administrator login.
- Does it apply to youThis applies if a user can add website code with restricted attributes on a site using the paid version of the tool where the language links use script provided values.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this less critical. Fix it with the next routine update.
Tell your developerUpdate Translate Drupal with GTranslate to 3.0.5.
For developers: what the fix changed
The fix adds a check at the beginning of the IIFE in multiple JavaScript files (e.g., `js/dropdown.js`, `js/dwf.js`) to ensure `document.currentScript` is an instance of `HTMLScriptElement`, preventing DOM clobbering attacks.
Also in this release The release also added a language weights configuration option, switched from sessionStorage to localStorage, and added lazy loading to flag images.
config/install/gtranslate.settings.yml+2 −1js/dropdown.js+14 −8 fixjs/dwf.js+14 −21 fixjs/fc.js+16 −9 fixjs/fd.js+16 −9 fixjs/flags.js+16 −9 fixjs/float.js+15 −9 fixjs/fn.js+16 −10 fixjs/globe.js+15 −9js/lc.js+15 −9js/ln.js+15 −10js/popup.js+15 −10