Linked Field
It enables administrators to link the output of a field to a URL or to the value of another field.
A content editor could add malicious code into specific fields. This code could reveal secret website settings like passwords or system keys. This could let someone read or alter restricted data.
- Who could do thisOnly someone with a login on your site.
- Does it apply to youA site is affected if an attacker has an access right to create or edit content in a field that has this module enabled in its display settings.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Linked Field to 8.x-1.8.
For developers: what the fix changed
The fix alters the entity display build hook in the main module file to output the linked HTML as plain markup rather than an inline template. This ensures that user provided field content is not evaluated as Twig code.
Also in this release The release also adds validation for the configuration form, stringifies class attributes, and updates continuous integration testing variables.
.gitlab-ci.yml+7 −4README.md+36 −9composer.json+8 −0linked_field.module+20 −7 fixsrc/Form/ConfigForm.php+23 −1src/LinkedFieldManager.php+4 −0