—
DRUPAL-CONTRIB-2021-028
Details
This advisory addresses a similar issue to [Drupal core - Moderately critical - Cross Site Request Forgery - SA-CORE-2021-006](https://www.drupal.org/sa-core-2021-006).
The Entity Embed module provides a filter to allow embedding entities in content fields. In certain circumstances, the filter could allow an unprivileged user to inject HTML into a page when it is accessed by a trusted user with permission to embed entities. In some cases, this could lead to cross-site scripting.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist:https://packages.drupal.org/8/drupal/entity_embed
Introduced in:
0Fixed in: 1.2.0Upgrade drupal/entity_embed to 1.2.0 or newer (ecosystem packagist:https://packages.drupal.org/8).