TacJS
A person with an ordinary account could place specific code on a page to delete cookies. They could use this to alter data on the website. They could not view any private information.
- Who could do thisOnly someone with a login on your site.
- Does it apply to youThis applies if a person has the access right to insert specific information into a page.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate TacJS to 8.x-6.8.
For developers: what the fix changed
The provided diff does not contain the security fix, as it only shows minor emoji updates in the language files of the tarteaucitron.js library.
The fix is not clearly separable from the other changes in this release, so treat the summary above as a pointer rather than a finding.
Also in this release The release updated the tarteaucitron.js library to version 1.33.0 which included minor emoji updates in various language files.
assets/vendor/tarteaucitron.js/.gitignore+1 −0assets/vendor/tarteaucitron.js/README.md+11 −8assets/vendor/tarteaucitron.js/css/tarteaucitron.css+239 −55assets/vendor/tarteaucitron.js/css/tarteaucitron.min.css+0 −0assets/vendor/tarteaucitron.js/lang/tarteaucitron.ar.js+1 −1assets/vendor/tarteaucitron.js/lang/tarteaucitron.ar.min.js+1 −1assets/vendor/tarteaucitron.js/lang/tarteaucitron.bg.js+1 −1assets/vendor/tarteaucitron.js/lang/tarteaucitron.bg.min.js+1 −1assets/vendor/tarteaucitron.js/lang/tarteaucitron.ca.js+1 −1assets/vendor/tarteaucitron.js/lang/tarteaucitron.ca.min.js+1 −1assets/vendor/tarteaucitron.js/lang/tarteaucitron.cn.js+1 −0assets/vendor/tarteaucitron.js/lang/tarteaucitron.cn.min.js+1 −1