The Entity Browser module allows you to select entities from entity reference fields using a custom entity browser widget.
The module doesn't sufficiently sanitize the the tab titles, resulting in a stored cross-site scripting (XSS) vulnerability.
The vulnerability is mitigated by the fact an attacker must be able to insert HTML with specific attributes on a page that is displaying an entity browser.
Install the latest version:
- If you use the Entity Browser module, upgrade to Entity Browser 8.x-2.16
- Pierre Rudloff (prudloff) of the Drupal Security Team
- Julian Pustkuchen (anybody)
- Sascha Grossenbacher (berdir)
- Pierre Rudloff (prudloff) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Drew Webber (mcdruid) of the Drupal Security Team
- Pierre Rudloff (prudloff) of the Drupal Security Team