Media Folders
An ordinary account holder could add malicious code to the names and descriptions of media items or folders. This code could then run in the browser of another user to view restricted information or make unauthorised changes.
- Who could do thisOnly someone with a login on your site.
- Does it apply to youThis applies if an attacker has an access right to create or edit media items or folders.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Media Folders to 1.0.8.
For developers: what the fix changed
Removes `Markup::create()` from folder descriptions in `MediaFoldersUiBuilder` to allow Twig auto-escaping, properly escapes strings in `highlightSearchResult()` before applying markup, and applies the `striptags` filter to the description in the `media-folders-folder.html.twig` template.
Also in this release Added support for SVG Image Field, fixed multiple selection on Mac OS, injected TypedConfigManagerInterface into MediaFoldersConfigForm, and fixed an image preview issue.
js/common.js+1 −1js/folders.js+1 −1js/widget.js+1 −1src/Form/AddWidgetFileForm.php+3 −0src/Form/MediaFoldersConfigForm.php+11 −3src/MediaFoldersUiBuilder.php+10 −5 fixtemplates/media-folders-folder.html.twig+1 −1 fix