Project machine name: 
lottiefiles_field
Date: 
2022-June-29
Vulnerability: 
Cross Site Scripting
Affected versions: 
<1.0.3
Description: 

The Lottiefiles Field module enables you to integrate the lottiefiles features into your page.

The module does not sufficiently filter user-provided text on output, resulting in a Cross-Site Scripting (XSS) vulnerability.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission to create or edit content that has lottiefiles fields.

Solution: 

Install the latest version:

Reported By: 
Fixed By: 
Coordinated By: