Date
Severity
Moderately Critical
Vulnerability
Cross Site Scripting
Affected versions
<7.x-1.4

Description

The Bootstrap Carousel module creates Bootstrap-powered image/video carousels as Drupal nodes, supporting captions and embedded YouTube videos per slide.

The module's field formatter outputs the carousel caption directly without sanitization, and the carousel template prints the video ID field into HTML attributes without escaping.

This vulnerability is mitigated by the fact that exploiting it requires administrative permissions to create or edit Bootstrap Carousel nodes.

Solution

Install the latest version.

If you use the bootstrap simple carousel module for Drupal 7, upgrade to bootstrap_carousel 7.x-1.4:


Reported by

Fixed by

  • Tag1 D7ES

Coordinated by

  • Tag1 D7ES