Slick Carousel
An administrator account could add malicious code to the buttons of a sliding gallery. This code would run in the browser of anyone visiting the page. The administrator could use this to read hidden information or change content on the website.
- Who could do thisOnly someone with an administrator login.
- Does it apply to youAny site using this module.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Slick Carousel to the latest release.
For developers: what the fix changed
The code change for this release could not be fetched from git.drupalcode.org.