Menu Link Attributes
It allows administrators to add extra details to menu links and their container elements.
An administrator could add unsafe text to website menus. This text could run malicious scripts when other people visit the page. This could let someone read or change private data.
- Who could do thisOnly someone with an administrator login.
- Does it apply to youA site is affected if an attacker has access rights to administer menus and use menu link attributes, and an unsafe container attribute is already configured.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Menu Link Attributes to 8.x-1.8.
For developers: what the fix changed
The fix introduces the menu_link_attributes_is_allowed_attribute_name and menu_link_attributes_filter_attributes functions in menu_link_attributes.module to validate and sanitise configuration. It applies these checks in the validateForm method of ConfigForm.php and includes an update hook in menu_link_attributes.install to strip unsafe attributes.
Also in this release The release also updates configuration descriptions and adds functional tests for the new validation.
config/install/menu_link_attributes.config.yml+2 −2menu_link_attributes.install+28 −0 fixmenu_link_attributes.module+78 −2 fixsrc/Form/ConfigForm.php+14 −1 fix