—
DRUPAL-CONTRIB-2026-080
상세
This module provides a better UI for managing and selecting Media entities in a folder structure.
The module doesn't sufficiently sanitize the names and descriptions of media items and folders when they are displayed in the media browser, resulting in a stored cross-site scripting (XSS) vulnerability.
This vulnerability is mitigated by the fact that an attacker must have a role with permission to create or edit media items or folders.
이 버전이 영향받나요?
사용 중인 패키지 버전을 입력하면 즉시 평가합니다.
영향 패키지
Packagist:https://packages.drupal.org/8 / drupal/media_folders
최초 영향 버전:
0 수정 버전: 1.0.8 Upgrade drupal/media_folders to 1.0.8 or newer (ecosystem packagist:https://packages.drupal.org/8).