editoria11yThis module runs a client-side accessibility checker that automatically reports results to dashboard views over an API.
The module incorrectly described a permission as a "view" permission when it grants edit and delete access to module data, resulting in a potential access bypass.
If you use the Editoria11y module, update the module and review permissions.
- If you use the Editoria11y module version 2.2.x, upgrade to editoria11y 2.2.23.
- If you use the Editoria11y module version 3.0.x, upgrade to editoria11y 3.0.9.
Review permissions: Make sure anonymous or untrusted authenticated users have not been given permission to use the checker. The permission is labeled as:
- View Editoria11y checker up to and including 2.2.22/3.0.8, and
- Run Editoria11y checker and report results with 2.2.23/3.0.9.
- Swan Kalata (akalata) of the Drupal Security Team
- Bram Driesen (bramdriesen) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Jess (xjm) of the Drupal Security Team