{"id":"DRUPAL-CONTRIB-2023-024","details":"This module enables you to create dynamic layouts and add sample color palettes for color selection hints via its UI.\n\nThe module doesn't sufficiently sanitize the module's settings in certain scenarios leading to a Cross Site Scripting vulnerability.\n\nThis vulnerability is mitigated by the fact that an attacker must have a role with the permissions \"administer gridstack\".","modified":"2026-09-10T03:45:54.640960247Z","published":"2023-06-28T17:03:36Z","references":[{"type":"WEB","url":"https://www.drupal.org/sa-contrib-2023-024"}],"affected":[{"package":{"name":"drupal/gridstack","ecosystem":"Packagist:https://packages.drupal.org/8","purl":"pkg:composer/drupal/gridstack?repository_url=https:%2F%2Fpackages.drupal.org%2F8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.11.0"}],"database_specific":{"constraint":"\u003c2.11"}}],"database_specific":{"affected_versions":"\u003c2.11","source":"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/gridstack/DRUPAL-CONTRIB-2023-024.json"}}],"schema_version":"1.9.0","credits":[{"name":"Mitch Portier","contact":["https://www.drupal.org/user/2284182"]}]}