Obfuscate
The module fails to clean up text entered by a person with an ordinary account when it is processed by a template. This flaw could allow that person to view information they should not see. They could also alter or add information on the website.
- Who could do thisOnly someone with a login on your site.
- Does it apply to youThis applies if the site uses the ROT13 encoding method and allows people to enter content that is processed by the template filter of the module.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Obfuscate to 2.0.2.
For developers: what the fix changed
The fix sanitises user input by applying `Xss::filter()` and `Html::escape()` in `ObfuscateMailROT13.php` and `ObfuscateMail.php`, and corrects the Twig function registration in `TwigExtension.php`.
Also in this release The release updates plugin annotations to PHP 8 attributes, modifies the configuration schema, adds Drupal 11 support, and adds automated tests.
config/schema/obfuscate.schema.yml+8 −8obfuscate.info.yml+1 −1src/ObfuscateMailROT13.php+6 −3 fixsrc/Plugin/Field/FieldFormatter/ObfuscateFieldFormatter.php+11 −11src/Plugin/Filter/ObfuscateMail.php+15 −10 fixsrc/TwigExtension.php+5 −4 fix