Responsive Favicons
The module does not filter text entered by an administrator. Someone could use this to view restricted information or modify website records.
- Who could do thisOnly someone with an administrator login.
- Does it apply to youA site is affected if an attacker has an account with the access right to administer responsive favicons.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Responsive Favicons to 2.0.2.
For developers: what the fix changed
The fix adds the restrict access flag to the administer responsive favicons permission in responsive_favicons.permissions.yml to mitigate the cross site scripting vulnerability by warning that the permission is for trusted users only.
responsive_favicons.permissions.yml+1 −0 fix