DRUPAL-CONTRIB-2023-043

See a problem?
Import Source
https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/highlight_php/DRUPAL-CONTRIB-2023-043.json
JSON Data
https://api.osv.dev/v1/vulns/DRUPAL-CONTRIB-2023-043
Published
2023-09-06T15:23:32Z
Modified
2025-12-10T23:33:24.490614Z
Summary
[none]
Details

Provides highlight.php integration to Drupal, allowing <code> blocks to be automatically highlighted with the correct language.

The module's Twig function doesn't sufficiently filter user-entered data.

References
Credits

Affected packages

Packagist:https://packages.drupal.org/8 / drupal/highlight_php

Package

Name
drupal/highlight_php
Purl
pkg:composer/drupal/highlight_php

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.0.1
Database specific
{
    "constraint": "< 1.0.1"
}

Database specific

affected_versions
"< 1.0.1"
source
"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/highlight_php/DRUPAL-CONTRIB-2023-043.json"