Mermaid Diagram Field
An ordinary account on the site could view diagram content in a pop up window without the correct access rights. They could see hidden charts meant for other users. They could not alter the diagrams.
- Who could do thisOnly someone with a login on your site.
- Does it apply to youThis applies if the pop up display option is turned on for the diagram field or if the attacker knows the exact web address of the pop up.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Mermaid Diagram Field to 1.0.10.
For developers: what the fix changed
The fix changes MermaidModalController::build in src/Controller/MermaidModalController.php to load the default revision instead of the latest revision and adds explicit view access checks for the entity and the field.
Also in this release Added a hook for CSV export in mermaid_diagram_field.module.
mermaid_diagram_field.module+54 −0src/Controller/MermaidModalController.php+10 −3 fix