Elysia Cron on Drupal maintenance support plans 6? Audit your permissions!

As you may know, Drupal maintenance support plans 6 has reached End-of-Life (EOL) which means the Drupal maintenance support plans Security Team is no longer doing Security Advisories or working on security patches for Drupal maintenance support plans 6 core or contrib modules – but the Drupal maintenance support plans 6 LTS vendors are and we’re one of them!Today, a security update for Elysia Cron was released for Drupal maintenance support plans 7 per the SA-CONTRIB-2020-062 security advisory.All the update does is mark the permission to administer Elysia Cron as “dangerous” because it allows users to execute arbitrary PHP code. This is by design, it’s an explicity feature of Elysia Cron – if it wasn’t intended by the module authors it would have been a Remote Code Execution vulnerability. However, users might not be aware that permission grants the ability to execute PHP, hence the security advisory!Unfortunately, there isn’t a way to mark a permission as dangerous under Drupal maintenance support plans 6. There isn’t even a way to have seperate machine name and human-readable labels for permissions, so there isn’t a straight-forward way to add a user visible message. :-(So, the Drupal maintenance support plans 6 Long-Term Support vendors (us included) have decided to simply announce the problem and ask anyone using the Elysia Cron to audit which users/roles have the “administer elysia_cron” permission and make sure it’s OK that they can execute arbitrary PHP code.We’re going to be auditting the permission on our client’s sites, so, if you’re one of our customers – no need to worry! We’ll contact you if we have any concerns.If you’d like us to handle this and similar issues, as well as have all your Drupal maintenance support plans 6 modules to receive security updates and have the fixes deployed the same day they’re released, please check out our D6LTS plans.
Source: New feed

This article was republished from its original source.
Call Us: 1(800)730-2416

Pixeldust is a 20-year-old web development agency specializing in Drupal and WordPress and working with clients all over the country. With our best in class capabilities, we work with small businesses and fortune 500 companies alike. Give us a call at 1(800)730-2416 and let’s talk about your project.

FREE Drupal SEO Audit

Test your site below to see which issues need to be fixed. We will fix them and optimize your Drupal site 100% for Google and Bing. (Allow 30-60 seconds to gather data.)

Powered by

Elysia Cron on Drupal maintenance support plans 6? Audit your permissions!

On-Site Drupal SEO Master Setup

We make sure your site is 100% optimized (and stays that way) for the best SEO results.

With Pixeldust On-site (or On-page) SEO we make changes to your site’s structure and performance to make it easier for search engines to see and understand your site’s content. Search engines use algorithms to rank sites by degrees of relevance. Our on-site optimization ensures your site is configured to provide information in a way that meets Google and Bing standards for optimal indexing.

This service includes:

  • Pathauto install and configuration for SEO-friendly URLs.
  • Meta Tags install and configuration with dynamic tokens for meta titles and descriptions for all content types.
  • Install and fix all issues on the SEO checklist module.
  • Install and configure XML sitemap module and submit sitemaps.
  • Install and configure Google Analytics Module.
  • Install and configure Yoast.
  • Install and configure the Advanced Aggregation module to improve performance by minifying and merging CSS and JS.
  • Install and configure Schema.org Metatag.
  • Configure robots.txt.
  • Google Search Console setup snd configuration.
  • Find & Fix H1 tags.
  • Find and fix duplicate/missing meta descriptions.
  • Find and fix duplicate title tags.
  • Improve title, meta tags, and site descriptions.
  • Optimize images for better search engine optimization. Automate where possible.
  • Find and fix the missing alt and title tag for all images. Automate where possible.
  • The project takes 1 week to complete.