VDB
Sign up
—

DRUPAL-CONTRIB-2023-016

Details

The Iubenda Integration module provides a custom block to provide a link to the Iubenda privacy policy. On this block, a custom prefix and suffix text can be entered.

The module does not sufficiently filter the block text fields on output, resulting in a Cross-Site Scripting (XSS) vulnerability.

This vulnerability is mitigated by the fact that an attacker must have a role with permission to use the layout builder on content, edit the layout, or with the "Administer blocks" permission.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist:https://packages.drupal.org/8/drupal/iubenda_integration
Introduced in: 0Fixed in: 4.0.1

Upgrade drupal/iubenda_integration to 4.0.1 or newer (ecosystem packagist:https://packages.drupal.org/8).

References