VDB
Sign up
—

DRUPAL-CONTRIB-2022-042

Details

The Drupal Embed module provides a filter to allow embedding various embeddable items like entities in content fields.

In certain circumstances, the filter could allow an unprivileged user to inject HTML into a page when it is accessed by a trusted user with permission to embed items. In some cases, this could lead to Cross-Site Request Forgery.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist:https://packages.drupal.org/8/drupal/embed
Introduced in: 0Fixed in: 1.5.0

Upgrade drupal/embed to 1.5.0 or newer (ecosystem packagist:https://packages.drupal.org/8).

References