AT Internet Piano Analytics
An administrator could put malicious code into text fields on the website. This code could then run when other people view the page. The attacker could use this to view hidden information or change content on the site.
- Who could do thisOnly someone with an administrator login.
- Does it apply to youThis applies if a user has the access right to manage the analytics service.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate AT Internet Piano Analytics to 1.0.1 or 2.3.1, whichever branch you are on.
For developers: what the fix changed
The release diff is linked below. No summary of the fix has been written for this one.
pianoanalytics.permissions.yml+1 −0