Ray Enterprise Translation
The module does not protect several administrative pages against forged requests. Anyone without logging in could trick a privileged user into visiting a crafted page that changes translation settings or uploads new translations. They could not read any restricted data.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youAny site using this module.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Ray Enterprise Translation to 4.1.4, 11.0.4 or 4.0.4, whichever branch you are on.
For developers: what the fix changed
Adds the `_csrf_token` requirement to multiple administrative routes in `lingotek.routing.yml` and implements manual CSRF token validation for POST and DELETE requests in `LingotekDashboardController::endpoint`.
Also in this release Added basic authentication for Lingotek notification callbacks.
config/schema/lingotek.schema.yml+8 −0lingotek.routing.yml+16 −1 fixlingotek.services.yml+3 −0src/Access/LingotekNotifyAccessCheck.php+147 −0src/Controller/LingotekControllerBase.php+33 −0src/Controller/LingotekDashboardController.php+10 −0 fixsrc/Controller/LingotekNotificationController.php+0 −4src/Controller/LingotekSetupController.php+5 −1src/Form/LingotekAccountDisconnectForm.php+2 −0src/Form/LingotekConfigFormBase.php+34 −0src/Form/LingotekSettingsDefaultsForm.php+5 −1src/Form/LingotekSettingsTabUtilitiesForm.php+16 −7