This module enables you to add dynamic caption support to PhotoSwipe image galleries.
The module doesn't sufficiently sanitize user-supplied input (such as image alt tags) in its dynamic caption script, leading to a Cross-Site Scripting (XSS) vulnerability.
This vulnerability is mitigated by the fact that an attacker must have a role that permits them to enter HTML content.
Install the latest version:
- If you use the photoswipe_dynamic_caption module, upgrade to photoswipe 5.0.9
- Pierre Rudloff (prudloff) of the Drupal Security Team
- Bram Driesen (bramdriesen) of the Drupal Security Team
- Joshua Sedler (grevil)
- Pierre Rudloff (prudloff) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Pierre Rudloff (prudloff) of the Drupal Security Team