Monster Menus
An ordinary account on the site could add malicious code to a page name. This code would run when someone else views the built in tree browser. The attacker could use this to read private data or change content on the site.
- Who could do thisOnly someone with a login on your site.
- Does it apply to youA site is affected if an attacker has the ability to create pages where the title supports HTML code.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Monster Menus to 9.5.3.
For developers: what the fix changed
The fix introduces a new `_mm_content_escape_name` function in `mm_content.inc` that sanitises page names using `strip_tags` and `Xss::filter`, and applies it to the return values of `mm_content_expand_name` and `mm_content_get_name`.
Also in this release Added a functional JavaScript test to ensure JavaScript in page names is not evaluated.
mm_content.inc+12 −7 fix