Server side cross-site scripting In drupal/webform
Description
The Webform module allows site builders to create forms, collect submissions, and configure access to forms and submission data.
Webform includes a submodule called Webform Entity Print. This submodule doesn't sufficiently limit access to its print templates. When the submodule is enabled, a user with permissions to create a webform can exploit cross-site scripting (XSS) in submodule settings.
This vulnerability is mitigated by the fact that an attacker must have a role with create webform and edit own webform permissions, and the Webform Entity Print module must be enabled.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
packagist | 6.2.12, 6.3.1 |
Aliases