—
DRUPAL-CONTRIB-2024-071
Details
This module allows a site builder to create multi-step entity forms leveraging the Field Group field type plugins.
The module doesn't escape plain text administrative configurations. An attacker with admin access could inject arbitrary JavaScript code.
This vulnerability is mitigated by the fact that an attacker must have a role with the 'administer [entity\_type] form display' permission allowing access to configure entity form displays.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist:https://packages.drupal.org/8/drupal/entity_form_steps
Introduced in:
0Fixed in: 1.1.4Upgrade drupal/entity_form_steps to 1.1.4 or newer (ecosystem packagist:https://packages.drupal.org/8).