Views Share
It enables administrators to share a view of content within another website.
A visitor could trigger heavy database searches by guessing hidden web addresses. They could slow down the website. They could not see any hidden data or alter any website content.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youA site is affected if an attacker knows the specific IDs of the view and display.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Views Share to 2.0.1.
For developers: what the fix changed
Adds an access check for the display ID to the view object in the preview, oembed, and modal methods of the ViewsShareController class.
Also in this release Updates the oembed method return type and changes how the format parameter is retrieved to resolve PHPStan issues.
src/Controller/ViewsShareController.php+5 −5 fix