WissKI
Anyone without logging in could submit malicious details through a web address to bypass access checks in the image viewer. They could view hidden image annotations and modify certain research records. They could not access or alter every piece of information on the website.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youA site is affected if it uses the Mirador image viewer feature.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this critical. Cyber Essentials expects a fix within 14 days. Do it this week.
Tell your developerUpdate WissKI to 8.x-4.2.
For developers: what the fix changed
The fix restricts session writes in WisskiMiradorApiController to only allow the mirador key, preventing arbitrary data from being stored in the session.
wisski_mirador/src/Controller/WisskiMiradorApiController.php+3 −1 fix