—
DRUPAL-CONTRIB-2020-002
Details
The SpamSpan module obfuscates email addresses to help prevent spambots from collecting them.
This module contains a spamspan twig filter which doesn't sanitize the passed HTML string.
This vulnerability is mitigated by the fact that sites must have custom twig template files that use the SpamSpan filter on a field that an attacker could populate. By default the SpamSpan module does not use the vulnerable twig filter.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist:https://packages.drupal.org/8/drupal/spamspan
Introduced in:
1.0.0No fixed version published yet for drupal/spamspan. Pin to a known-safe version or switch to an alternative.