Skip to main content

Colorbox - Moderately critical - Cross Site Scripting - D7SECURITY-SA-CONTRIB-2025-002

· One min read

2025/04/24

Project: Colorbox

Security risk: Moderately critical 14/25 AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:All

Vulnerability: Cross Site Scripting

Affected versions: <7.x-2.20

Description

Colorbox is a module that allows Images, and iframed or inline content to be displayed in a modal above the current page.

The Colorbox module doesn't sufficiently sanitize data attributes before opening modals.

This vulnerability is mitigated by the fact that an attacker must have a role with permission to enter HTML tags containing specific data attributes.

Solution

Install the latest version.

If you use the Colorbox module for Drupal 7, upgrade to Colorbox 7.x-2.20.

Reported By:

Fixed By:

Coordinated By: