Colorbox Inline
A user with an account could add malicious website code by using specific data attributes. They could view or change certain restricted information on the page. They could not read or change all the data on the website.
- Who could do thisOnly someone with a login on your site.
- Does it apply to youThis applies if a user has the access right to enter website code containing specific data attributes.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Colorbox Inline to 2.1.1.
For developers: what the fix changed
The fix in js/colorbox_inline.js validates that the data-colorbox-inline attribute is a string without angle brackets and uses $(document).find() instead of passing the selector directly to jQuery to prevent cross site scripting.
Also in this release Fixed a PHPUnit deprecation for #[RunTestsInSeparateProcesses].
js/colorbox_inline.js+21 −16 fix