contao-components/colorbox is vulnerable to Cross-Site Scripting (XSS)
30
Low Risk
Colorbox builds each gallery caption from the triggering element's title value and inserts it into the page with jQuery's .html(). Untrusted or externally influenced title text is rendered as raw HTML, so a < character in that value opens new markup or script tags inside the caption. Viewing a Colorbox item whose title contains such markup executes it in the page. The fix escapes < characters in the title before it is rendered.
You are affected if you are using a version that falls within the vulnerable range and you render a Colorbox item whose triggering element has a title built from untrusted or externally influenced content.
contao-components/colorbox is vulnerable to Cross-Site Scripting (XSS) in versions 1.0.0 - 1.6.4.2.
Upgrade the contao-components/colorbox library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.