MathJax: LaTeX for Drupal
It integrates a mathematical rendering library into a website.
A user could hide malicious scripts inside math formulas. These scripts could run in the web browser of anyone reading the page. This could let someone read or alter hidden data.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youAny site using this module.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this critical. Cyber Essentials expects a fix within 14 days. Do it this week.
Tell your developerUpdate MathJax: LaTeX for Drupal to 4.1.2.
For developers: what the fix changed
The fix updates the default configuration in config/install/mathjax.settings.yml and the library definition in mathjax.module to include the Safe mode parameter in the content delivery network URL. It also adds a requirements check and an update hook in mathjax.install to warn administrators and update existing configurations.
Also in this release The release updates an insecure content delivery network version warning in mathjax.install.
config/install/mathjax.settings.yml+1 −1 fixmathjax.install+56 −8 fixmathjax.module+1 −1 fix