PhotoSwipe - Responsive JavaScript Modal Image Gallery
The module does not properly clean user supplied text like image descriptions. A user with an ordinary account could read hidden data or change data on the website.
- Who could do thisOnly someone with a login on your site.
- Does it apply to youAny site using this module where an attacker has an access right that permits them to enter HTML content.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate PhotoSwipe - Responsive JavaScript Modal Image Gallery to 5.0.9.
For developers: what the fix changed
The fix escapes the caption title using Drupal.checkPlain in modules/photoswipe_dynamic_caption/js/photoswipe_dynamic_caption.init.js and removes the previous escaping in modules/photoswipe_dynamic_caption/photoswipe_dynamic_caption.module.
Also in this release The release also improves media translation context handling in src/ImageDTO.php.
modules/photoswipe_dynamic_caption/js/photoswipe_dynamic_caption.init.js+3 −1 fixmodules/photoswipe_dynamic_caption/photoswipe_dynamic_caption.module+4 −2 fixsrc/ImageDTO.php+6 −2