- Colorbox module versions prior to 1.x-2.16.0.
The colorbox module is a light-weight, customizable lightbox plugin for jQuery that allows images or content can be displayed in a popup or modal "lightbox" above the current page.
Colorbox did not sufficiently sanitize urls, captions, or the title attribute in some situations.
This vulnerability is mitigated by the fact that your site must have enabled the Colorbox feature to use captions, title attributes, and/or external URLs in order to have been at risk. Additionally, an attacker must have had access to an unsanitized text format, or a format that was otherwise adapted to allow the use of colorboxes.
Upgrade your site to the most recent version of the colorbox module. Download available on the Colorbox module 1.x-2.16.0 release page.