Search API Autocomplete
Anyone without logging in could use a test script to run malicious code in the browser of a visitor. They could use this to view restricted information or make unauthorised changes on the site.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youThis applies if the web server is configured to display warning messages to users.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Search API Autocomplete to 8.x-1.12.
For developers: what the fix changed
Moves the JSON content-type header to the start of `search_api_autocomplete_test_custom_autocomplete_callback()` in `custom_autocomplete_script.php` and ignores non-string input to prevent XSS via PHP warnings.
Also in this release Adapted to the deprecation of hook_requirements() and fixed failing tests against newer Drupal versions.
.gitlab-ci.yml+14 −4.ignored-deprecations.txt+80 −0CHANGELOG.txt+6 −0phpstan.neon+30 −2search_api_autocomplete.install+6 −53search_api_autocomplete.services.yml+7 −1src/Hook/SearchApiAutocompleteHooks.php+97 −0src/Utility/PluginHelper.php+7 −25