—
DRUPAL-CONTRIB-2022-026
Details
This module provides an entity relationship hierarchy tree widget for an entity reference field.
The module doesn't sufficiently filter on output, leading to a Cross Site Scripting vulnerability.
This vulnerability is mitigated by the fact that an attacker must have a role with the permission to modify an entity that is the reference to a field.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist:https://packages.drupal.org/8/drupal/entity_reference_tree
Introduced in:
0Fixed in: 2.0.2Upgrade drupal/entity_reference_tree to 2.0.2 or newer (ecosystem packagist:https://packages.drupal.org/8).