Project:
Date:
2023-September-06
Vulnerability:
Cross Site Scripting
Affected versions:
< 1.0.1
Description:
Provides highlight.php integration to Drupal, allowing <code> blocks to be automatically highlighted with the correct language.
The module's Twig function doesn't sufficiently filter user-entered data.
Solution:
Install the latest version:
- If you use the highlight.php module, upgrade to highlight.php 1.0.1
Reported By:
Fixed By:
Coordinated By:
- Benji Fisher of the Drupal Security Team
- Damien McKenna of the Drupal Security Team
- Greg Knaddison of the Drupal Security Team