Inline Entity Form Dialog
It renders forms for pieces of content inside a pop up window instead of placing them directly on the page.
A user who can view administrative pages could alter content they do not normally control. They could read restricted details and change information inside popup forms.
- Who could do thisOnly someone with a login on your site.
- Does it apply to youA site is affected if an attacker has an access right to access administration pages.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Inline Entity Form Dialog to 1.0.6.
For developers: what the fix changed
The fix introduces explicit entity create and update access checks inside the add and edit methods of the dialog controller. This ensures users cannot bypass entity level permissions when using the dialog widget.
Also in this release Bundle labels now have HTML tags stripped before output and a boolean cast was added to a widget setting to prevent type errors.
src/Controller/InlineEntityFormDialogController.php+15 −0 fixsrc/Plugin/Field/FieldWidget/InlineEntityFormDialogWidget.php+7 −7