Skip to main content
Drupal is a registered trademark of Dries Buytaert
Release: Views Bootstrap 5.5.4 — Minor update available for module views_bootstrap (5.5.4). Release: ChatGPT Ads 1.0.3 — Minor update available for module chatgpt_ads (1.0.3). Release: Opensolr Search 5.1.3 — Minor update available for module opensolr_search (5.1.3). Release: ServiceM8 Webform Integration 1.2.1 — Minor update available for module servicem8_webform (1.2.1). Release: PostfixAdmin 1.0.0 — Initial release available for module postfix_admin (1.0.0)! Release: MCP Sentinel 2.28.2 — Minor update available for module mcp_sentinel (2.28.2). Release: Rightup theme 1.0.2 — Minor update available for theme vartheme_bs5_rightup (1.0.2). Release: ip_analyser 1.0.3 — Minor update available for module ip_analyser (1.0.3). Security Coverage: Microsoft Azure AI — Module ai_provider_azure now has official Drupal security advisory coverage. Module Revived: Liquid Voting 2.0.1 — Module liquid_voting updated after 6 months of inactivity (2.0.1).

PHP

Security revoked
View on drupal.org

The PHP module adds dynamic functionality based on direct PHP input in the following areas:

  1. A filter format for use with text formats. A PHP Code text format is directly installed with the module.
  2. Block visibility based on PHP code input.
  3. Views contextual filter and argument validator plugins based on PHP code input.

Warning

Enabling this module can cause security and performance issues as it allows users to execute PHP code on your site. A much better alternative is creating custom modules for the things you embedded PHP for previously. Such as a custom module defining a block with your own code, rather than a custom block with PHP in it.

The module may break your site

The module has no way to validate the PHP code before executing it. When using the PHP filter, it is very easy to input incorrect code to the page that leads to WSOD (white screen of death) problems. This is caused by running the PHP code leading to fatal errors. In this case nothing is displayed on the page. It is very easy to get into this situation and may require direct access to the server to get out of it.

The module exposes all website data to users with permission to use it

Any user with permission to use the filter will be able to access all data available to Drupal. It is not possible to limit access to personal data or private information or unpublished content for users that have permission to use this filter. Even with many secured servers, it may be possible to scan the server for additional files. If you can read the settings.php file of another Drupal installation, then you will be able to access its database as well.

The module gives very wide access to the server filesystem and executables

Any user with permission to use the filter will be able to run executables through PHP and access and modify all files that the webserver user has access to. With this access, there are a million ways to take control of the site or server.

The module makes other security issues a lot more dangerous

For example, if any of your components have cross site scripting (XSS) issues on pages that also have PHP input capability, that means the XSS is escalated to potential to fully compromise the data and even the whole server, giving access to personal data to hackers.

Your site may become a spam source

A frequent goal of a hacker is to use your server to send spam. Gaining access to PHP will allow the user to send emails at will.

Related

Read more at #1203886: Remove the PHP module from Drupal core.

Depends on

Dependencies of the latest stable release

No dependencies recorded for this project.

Required by

Tracked projects that depend on this one

No tracked projects depend on this one yet.

Activity

Tracked releases
1
Tracked since
Apr 2024
Latest release
2 years ago
Releases (12 mo)
0
Maintenance
Dormant

Releases

Version Type Core Release date
8.x-1.2 Stable Apr 4, 2024