Leaflet
It provides integration with a specific mapping library to display maps.
A content editor could place malicious scripts in map titles. These scripts could run in the web browser of anyone viewing the map. This could allow someone to see or change restricted data.
- Who could do thisOnly someone with a login on your site.
- Does it apply to youA site is affected if an attacker has an access right to create or edit content that is used in a map.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Leaflet to 10.4.13.
For developers: what the fix changed
Removes entity decoding of tooltip values in the LeafletMap style plugin and updates the JavaScript alternative text extraction to use DOMParser instead of a regular expression to prevent cross site scripting.
Also in this release Adds configuration schema settings for popup and marker clustering options, updates JavaScript to preserve original features implementation, and removes underline tags from user interface strings.
config/schema/leaflet.schema.yml+12 −0css/leaflet_general.css+3 −3js/leaflet.drupal.js+1 −1 fixmodules/leaflet_markercluster/leaflet_markercluster.drupal.js+18 −0modules/leaflet_views/src/Plugin/views/style/LeafletMap.php+2 −4 fixsass/leaflet_general.scss+3 −3src/LeafletSettingsElementsTrait.php+11 −11src/Plugin/Field/FieldFormatter/LeafletDefaultFormatter.php+42 −12