leafletThe Leaflet module provides integration with the Leaflet JS mapping library.
Under certain circumstances, when the Leaflet field formatter builds a map it does not filter content titles, leading to a stored cross-site scripting vulnerability.
This vulnerability is mitigated by the fact an attacker needs to have permission to create or edit content that is used in a Leaflet map.
Install the latest version:
- If you use the Leaflet module, upgrade to release 10.4.13
- Swan Kalata (akalata) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team