Junglewise Threat Intelligence

DRUPAL-CONTRIB-2019-030 - This module enables you to create facet-filters for results of a search query and exposes them as blocks The module doesn't sufficiently es

Severity: info · Published 2019-02-27

Technologies: Packagist:Https://Packages.Drupal.Org/8 Drupal/Facets. Vendors: Packagist:Https://Packages.Drupal.Org/8.

Executive brief

This module enables you to create facet-filters for results of a search query and exposes them as blocks

The module doesn't sufficiently escape HTML under the scenario leading to a Cross Site Scripting (XSS) vulnerability.

This vulnerability is mitigated by two factors. First, an attacker must have a way to insert results in the dataset that is exposed as a facet before this can happen. The permission to inject malicious strings depends on the site's search configuration but could be available to any user who can create content in a site. Second, the site must be using the Javascript-based dropdown widget.

Affected products

  • packagist:https://packages.drupal.org/8 drupal/facets

Related threats