Date: 
2022-February-23
Vulnerability: 
Cross Site Scripting
Affected versions: 
<2.0.2
Description: 

This module provides an entity relationship hierarchy tree widget for an entity reference field.

The module doesn't sufficiently filter on output, leading to a Cross Site Scripting vulnerability.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission to modify an entity that is the reference to a field.

Solution: 

Install the latest version:

Reported By: 
Coordinated By: