Project
Date
Severity
Moderately Critical
Vulnerability
Cross Site Scripting
Affected versions
<7.x-1.4
Description
The Bootstrap Carousel module creates Bootstrap-powered image/video carousels as Drupal nodes, supporting captions and embedded YouTube videos per slide.
The module's field formatter outputs the carousel caption directly without sanitization, and the carousel template prints the video ID field into HTML attributes without escaping.
This vulnerability is mitigated by the fact that exploiting it requires administrative permissions to create or edit Bootstrap Carousel nodes.
Solution
Install the latest version.
If you use the bootstrap simple carousel module for Drupal 7, upgrade to bootstrap_carousel 7.x-1.4:
Reported by
Fixed by
- Tag1 D7ES
Coordinated by
- Tag1 D7ES