Inline Formatter Field
It allows site builders to use templates and style pieces of content with a field.
A user could place malicious commands in a text field. These commands could expose secret system data or run unsafe code on the server. This could let someone read or alter hidden information.
- Who could do thisOnly someone with a login on your site.
- Does it apply to youAny site using this module.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Inline Formatter Field to 4.2.0.
For developers: what the fix changed
Escapes curly braces in token replacements by converting them to HTML entities in the inline formatter display module and field formatter plugin, and refactors token fetching in the Views field plugin to prevent server side template injection.
Also in this release Adds the inline formatter field as an enforced dependency to the Ace Editor text format.
config/install/filter.format.iff_ace_editor.yml+4 −1inline_formatter_field.install+22 −0modules/inline_formatter_display/inline_formatter_display.module+12 −1 fixmodules/inline_formatter_views_field/src/Plugin/views/field/InlineFormatterViewsField.php+5 −21 fixsrc/Plugin/Field/FieldFormatter/InlineFormatterFieldFormatter.php+16 −1 fix