highlight.php - Moderately critical - Cross Site Scripting - SA-CONTRIB-2023-043

Project: highlight.phpDate: 2023-September-06Security risk: Moderately critical 13∕25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:DefaultVulnerability: Cross Site ScriptingAffected versions: < 1.0.1Description: Provides highlight.php integration to Drupal, allowing <code> blocks to be automatically highlighted with the correct language.
The module's Twig function doesn't sufficiently filter user-entered data.Solution: Install the latest version:

Reported By: 

Fixed By: 

Coordinated By: 

Path to article https://www.drupal.org/sa-contrib-2023-043