Webform Submissions Delete
The module does not properly restrict access to the delete page. A visitor could delete form submissions. They could not read any hidden data.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youAny site using this module.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Webform Submissions Delete to 8.x-1.2.
For developers: what the fix changed
The fix restricts access to the bulk delete form by changing the routing requirement in webform_submissions_delete.routing.yml from access content to webform.submission_purge_any and adds accessCheck(TRUE) to entity queries in src/Form/WebformResultsBulkDeleteForm.php.
Also in this release Added Drupal 11 compatibility and maintainer information.
README.md+3 −0composer.json+6 −1src/Form/WebformResultsBulkDeleteForm.php+2 −2 fixwebform_submissions_delete.info.yml+1 −1webform_submissions_delete.routing.yml+1 −1 fix