Webform - Critical - Access bypass - SA-CONTRIB-2020-018
Project: Webform
Date: 2020-May-13
Security risk: Critical 15∕25
Vulnerability: Access bypass
Description
This webform module enables you to build a 'Term checkboxes' element.
The module doesn't sufficiently check term 'view' access when rendering 'Term checkboxes' elements. Unpublished terms will always appear in the 'Term checkboxes' element.