VDB
Sign up
—

DRUPAL-CONTRIB-2019-062

Details

This module improves the Drupal login page with the new features and layout.

The module doesn't sufficiently filter input text in the administration pages text configuration inputs. For example, the login text field.

The vulnerability is mitigated by the fact it can only be exploited by a user with the "Administer super login" permission.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist:https://packages.drupal.org/8/drupal/super_login
Introduced in: 0Fixed in: 1.3.0

Upgrade drupal/super_login to 1.3.0 or newer (ecosystem packagist:https://packages.drupal.org/8).

References