VDB
Sign up
—

DRUPAL-CONTRIB-2025-029

Details

This module enables you to obfuscate email addresses, to avoid them being easily available to spammers.

The module doesn't sufficiently sanitise input when ROT13 encoding is used. This vulnerability is mitigated by the fact that an attacker must have a role with the ability to enter specific HTML tag attributes. In a default Drupal installation this would require the administrator role and use of the Full HTML text format. It also requires that the ROT13 encoding be enabled in Obfuscate settings.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist:https://packages.drupal.org/8/drupal/obfuscate
Introduced in: 0Fixed in: 2.0.1

Upgrade drupal/obfuscate to 2.0.1 or newer (ecosystem packagist:https://packages.drupal.org/8).

References