SafeDelete
The module does not properly clean up the titles of content when displaying the report. A user with an ordinary account could insert harmful scripts into a title which would run when someone views the report to read private information and change some data.
- Who could do thisOnly someone with a login on your site.
- Does it apply to youA site is affected if an attacker has the access right to create a piece of content that appears in the report.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate SafeDelete to 1.0.88.
For developers: what the fix changed
The fix removes the raw filter from the node title in the templates/safedelete-orphanedpages.html.twig template and sanitises the title using PlainTextOutput::renderFromHtml in safedelete.module.
safedelete.module+3 −2 fixtemplates/safedelete-orphanedpages.html.twig+1 −1 fix