Tawk.to - Live chat application
Anyone without logging in could trick a logged in user into performing actions they did not intend to do. They could read private chat logs and alter the chat settings. They could not take full control of the web server.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youAny site using this module.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this critical. Cyber Essentials expects a fix within 14 days. Do it this week.
Tell your developerUpdate Tawk.to - Live chat application to 3.0.4.
For developers: what the fix changed
The fix adds CSRF token requirements and restricts methods to POST for the `set_widget` and `remove_widget` routes in `tawk_to.routing.yml`. It also updates `TawkToWidgetController` to generate URLs with CSRF tokens and modifies `tawk-to-iframe.html.twig` to use these secure URLs when making requests.
Also in this release The release replaces jQuery with vanilla JavaScript in the iframe template, improves autoescaping in templates, and adds entity decoding for user details in `TawkToEmbedRender`.
src/Controller/TawkToWidgetController.php+75 −7 fixsrc/Service/TawkToEmbedRender.php+5 −4tawk_to.routing.yml+4 −0 fixtemplates/tawk-to-iframe.html.twig+55 −37 fixtemplates/tawk-to.html.twig+3 −1