Date: 
Wednesday, Feb 2nd, 2022
Advisory ID: 
BACKDROP-SA-CONTRIB-2022-007
Security risk: 
Moderately Critical
Vulnerability: 
Cross Site Scripting
Versions affected: 
  • Colorbox module versions prior to 1.x-2.16.0
Description: 

The colorbox module is a light-weight, customizable lightbox plugin for jQuery that allows images or content can be displayed in a popup or modal "lightbox" above the current page.

Colorbox did not sufficiently sanitize urls, captions, or the title attribute in some situations.

This vulnerability is mitigated by the fact that your site must have enabled the Colorbox feature to use captions, title attributes, and/or external URLs in order to have been at risk. Additionally, an attacker must have had access to an unsanitized text format, or a format that was otherwise adapted to allow the use of colorboxes.

Solution: 

Upgrade your site to the most recent version of the colorbox module. Download available on the Colorbox module 1.x-2.16.0 release page

Security email list

Backdrop maintains a security mailing list. Whenever a security release comes out, an email will be sent to everyone subscribed to that list, announcing the new release. Please follow the steps below to join the Security email list.

  1. Log in to backdropcms.org
  2. Edit your profile
  3. Switch to the "Subscriptions" tab
  4. Check the box labeled "Security updates"
  5. Save the form