—
DRUPAL-CONTRIB-2025-041
Details
Colorbox is a module that allows Images, and iframed or inline content to be displayed in a modal above the current page.
The Colorbox module doesn't sufficiently sanitize data attributes before opening modals.
This vulnerability is mitigated by the fact that an attacker must have a role with permission to enter HTML tags containing specific data attributes.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist:https://packages.drupal.org/8/drupal/colorbox
Introduced in:
0Fixed in: 2.1.3Upgrade drupal/colorbox to 2.1.3 or newer (ecosystem packagist:https://packages.drupal.org/8).