Theme Negotiation by Rules
The module uses insecure web requests to turn design rules on or off. Someone could trick an administrator into clicking a link to change these rules. They could not view private details but they could alter website settings.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youA site is affected if an attacker knows the internal system name of a design rule.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Theme Negotiation by Rules to 1.2.1.
For developers: what the fix changed
Adds CSRF token requirements to the enable and disable routes in theme_rule.routing.yml.
theme_rule.routing.yml+2 −0 fix