Tagify
A flaw in the dropdown menu allows scripts to be hidden inside the names of parent categories. Someone could run these scripts in the browser of another user to view private information or make unauthorised changes. They could not take full control of the website.
- Who could do thisOnly someone with a login on your site.
- Does it apply to youThis applies if the site gives users the access right to create or edit categories.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Tagify to 1.2.52.
For developers: what the fix changed
The fix sanitises parent taxonomy term names by wrapping `parentName` with `Drupal.checkPlain()` when generating the dropdown HTML in `js/tagify.js`. It also updates the `highlightMatchingLetters` function to escape segments individually, preventing HTML-entity corruption.
Also in this release The release also fixes `maxItems` handling in the facets widget and removes a broken Sortable dependency.
js/tagify.js+47 −50 fixmodules/tagify_facets/js/tagify-widget.js+3 −12modules/tagify_facets/tagify_facets.libraries.yml+0 −1