Background information

This is a followup to SA-CORE-2026-001.

Problem/Motivation

The error generated when the value of ?ajax_page_state[libraries] is invalid can be used to inject HTML.
This is not a XSS vulnerability because the HTML is sanitized with Xss::filter(), but it should still be prevented because it could make some reflected XSS easier to exploit.

Steps to reproduce

  1. Browse to /admin/config/development/logging and set "Error messages to display" to "Errors and warnings".
  2. As an anonymous user, browse to /user/login?ajax_page_state[libraries]=<b>foo (you might have to reload the page to see the error).
  3. The error contains the unescaped <b> HTML tag.

Proposed resolution

Filter out libraries that do not contain a /.
Test that libraries that contain a / but that contain HTML tags are not rendered as raw HTML.

Remaining tasks

User interface changes

Introduced terminology

API changes

None

Data model changes

Release notes snippet

Issue fork drupal-3603762

Command icon Show commands

Start within a Git clone of the project using the version control instructions.

Or, if you do not have SSH keys set up on git.drupalcode.org:

Comments

prudloff created an issue. See original summary.

prudloff’s picture

longwave made their first commit to this issue’s fork.

longwave’s picture

Status: Active » Needs review

Added various hardenings for the libraries parameter.

smustgrave’s picture

Status: Needs review » Needs work

Asked 1 question on the MR, but can we update the summary please (sorry to be that guy)

longwave’s picture

Issue summary: View changes
Status: Needs work » Needs review
smustgrave’s picture

Status: Needs review » Reviewed & tested by the community

Thanks no additional feedback!

  • catch committed fc039e59 on 11.4.x
    fix: #3603762 HTML injection in ajax_page_state GET parameter
    
    By:...

  • catch committed f3333be0 on 11.x
    fix: #3603762 HTML injection in ajax_page_state GET parameter
    
    By:...

  • catch committed 2fdf57a0 on main
    fix: #3603762 HTML injection in ajax_page_state GET parameter
    
    By:...
catch’s picture

Version: main » 11.4.x-dev
Status: Reviewed & tested by the community » Fixed

Committed/pushed to main and cherry-picked to 11.x and 11.4.x, thanks!

Now that this issue is closed, review the contribution record.

As a contributor, attribute any organization that helped you, or if you volunteered your own time.

Maintainers, credit people who helped resolve this issue.

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.