highlight.php - Moderately critical - Cross Site Scripting - SA-CONTRIB-2023-043
Project: highlight.phpDate: 2023-September-06Security risk: Moderately critical 13∕25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:DefaultVulnerability: Cross Site ScriptingAffected versions: < 1.0.1Description: Provides highlight.php integration to Drupal, allowing <code> blocks to be automatically highlighted with the correct language.
The module's Twig function doesn't sufficiently filter user-entered data.Solution: Install the latest version:
- If you use the highlight.php module, upgrade to highlight.php 1.0.1
Reported By:
Fixed By:
Coordinated By:
- Benji Fisher of the Drupal Security Team
- Damien McKenna of the Drupal Security Team
- Greg Knaddison of the Drupal Security Team