Ultimate Table Field
The page used to edit table cells is not properly protected. Anyone visiting the site could open this page and upload document files to the server. They could change or add some data but they could not read any private information.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youAny site using this module.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this critical. Cyber Essentials expects a fix within 14 days. Do it this week.
Tell your developerUpdate Ultimate Table Field to 2.0.1 or 1.1.1, whichever branch you are on.
For developers: what the fix changed
The fix introduces a new permission in ultimate_table_field.permissions.yml and applies it to the ultimate_table_field.open_modal_form route in ultimate_table_field.routing.yml. It also adds an access check to the modalLinkBuilder function in src/Element/UltimateTableTrait.php to hide the link for users without the permission.
Also in this release A post update hook was added to inform administrators about the new permission, and the README was updated.
README.md+10 −0src/Element/UltimateTableTrait.php+13 −5 fixultimate_table_field.permissions.yml+3 −0 fixultimate_table_field.post_update.php+13 −0ultimate_table_field.routing.yml+1 −1 fix