Siteimprove Analytics
The module does not properly clean the analytics identification code. An administrator account could exploit this to read some restricted data and change or add some data.
- Who could do thisOnly someone with an administrator login.
- Does it apply to youThis applies if an attacker has the access right to manage the analytics settings.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Siteimprove Analytics to 2.0.1.
For developers: what the fix changed
The fix escapes the Siteimprove Analytics code configuration value using Html::escape in the siteimprove_analytics_page_attachments function within siteimprove_analytics.module to prevent cross site scripting.
Also in this release Updates to the README.md file.
README.md+5 −5siteimprove_analytics.module+3 −1 fix