VDB
Sign up
—

DRUPAL-CONTRIB-2019-030

Details

This module enables you to create facet-filters for results of a search query and exposes them as blocks

The module doesn't sufficiently escape HTML under the scenario leading to a Cross Site Scripting (XSS) vulnerability.

This vulnerability is mitigated by two factors. First, an attacker must have a way to insert results in the dataset that is exposed as a facet before this can happen. The permission to inject malicious strings depends on the site's search configuration but could be available to any user who can create content in a site. Second, the site must be using the Javascript-based dropdown widget.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist:https://packages.drupal.org/8/drupal/facets
Introduced in: 0Fixed in: 1.3.0

Upgrade drupal/facets to 1.3.0 or newer (ecosystem packagist:https://packages.drupal.org/8).

References