VDB
Sign up
—

DRUPAL-CONTRIB-2025-043

Details

Block Class enables you to add custom attributes to blocks.

The module did not sufficiently sanitize custom attribute input, allowing for potential XSS attacks when malicious JavaScript was injected as a custom attribute.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission "administer block classes".

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist:https://packages.drupal.org/8/drupal/block_class
Introduced in: 4.0.0Fixed in: 4.0.1

Upgrade drupal/block_class to 4.0.1 or newer (ecosystem packagist:https://packages.drupal.org/8).

References