Location Selector
The module does not properly clean user input in one of its search filters. Anyone without logging in could use this to read any data on the site. They could also change any data on the site including code.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youThis applies if a list of content exists that uses the affected filter and accepts user input.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this critical. Cyber Essentials expects a fix within 14 days. Do it this week.
Tell your developerUpdate Location Selector to 8.x-1.3.
For developers: what the fix changed
The fix replaces string concatenation with parameterised queries in the query method of LocationSelectorFilter.php to prevent SQL injection.
src/Plugin/views/filter/LocationSelectorFilter.php+8 −3 fix