—
DRUPAL-CONTRIB-2025-043
Details
Block Class enables you to add custom attributes to blocks.
The module did not sufficiently sanitize custom attribute input, allowing for potential XSS attacks when malicious JavaScript was injected as a custom attribute.
This vulnerability is mitigated by the fact that an attacker must have a role with the permission "administer block classes".
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist:https://packages.drupal.org/8/drupal/block_class
Introduced in:
4.0.0Fixed in: 4.0.1Upgrade drupal/block_class to 4.0.1 or newer (ecosystem packagist:https://packages.drupal.org/8).