UI Icons
The module fails to clean up text provided by visitors. Anyone visiting the site could use this flaw to view private information. They could also alter or add new information to the website.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youThis applies if the site has enabled the UI Icons for CKEditor 5 feature.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this critical. Cyber Essentials expects a fix within 14 days. Do it this week.
Tell your developerUpdate UI Icons to 1.0.1 or 1.1.1, whichever branch you are on.
For developers: what the fix changed
Removes the unsanitised icon ID from the 404 response in IconFilterController to prevent reflected cross site scripting.
modules/ui_icons_ckeditor5/src/Controller/IconFilterController.php+1 −1 fix