PT-2022-38345 · Packagist · Drupal/Entity Reference Tree

Published

2022-02-23

·

Updated

2022-02-23

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
This module provides an entity relationship hierarchy tree widget for an entity reference field.
The module doesn't sufficiently filter on output, leading to a Cross Site Scripting vulnerability.
This vulnerability is mitigated by the fact that an attacker must have a role with the permission to modify an entity that is the reference to a field.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

DRUPAL-CONTRIB-2022-026

Affected Products

Drupal/Entity Reference Tree