PT-2023-37005 · Packagist · Drupal/Iubenda Integration

Published

2023-05-31

·

Updated

2023-05-31

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
The Iubenda Integration module provides a custom block to provide a link to the Iubenda privacy policy. On this block, a custom prefix and suffix text can be entered.
The module does not sufficiently filter the block text fields on output, resulting in a Cross-Site Scripting (XSS) vulnerability.
This vulnerability is mitigated by the fact that an attacker must have a role with permission to use the layout builder on content, edit the layout, or with the "Administer blocks" permission.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

DRUPAL-CONTRIB-2023-016

Affected Products

Drupal/Iubenda Integration