—
DRUPAL-CONTRIB-2023-016
Details
The Iubenda Integration module provides a custom block to provide a link to the Iubenda privacy policy. On this block, a custom prefix and suffix text can be entered.
The module does not sufficiently filter the block text fields on output, resulting in a Cross-Site Scripting (XSS) vulnerability.
This vulnerability is mitigated by the fact that an attacker must have a role with permission to use the layout builder on content, edit the layout, or with the "Administer blocks" permission.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist:https://packages.drupal.org/8/drupal/iubenda_integration
Introduced in:
0Fixed in: 4.0.1Upgrade drupal/iubenda_integration to 4.0.1 or newer (ecosystem packagist:https://packages.drupal.org/8).