it-securitynotifies AT lists.piratenpartei.de
Betreff: Sicherheitsankündigungen
Listenarchiv
[IT-SecNots] [Security-news] Diba carousel slider - Moderately critical - Cross Site Scripting (XSS) - SA-CONTRIB-2026-191
Chronologisch Thread
- From: security-news AT drupal.org
- To: security-news AT drupal.org
- Subject: [IT-SecNots] [Security-news] Diba carousel slider - Moderately critical - Cross Site Scripting (XSS) - SA-CONTRIB-2026-191
- Date: Wed, 23 Sep 2026 17:24:34 +0000
- Arc-authentication-results: i=2; smtp4.osuosl.org; dmarc=pass header.from=drupal.org; dkim=pass header.d=drupal.org header.i= AT drupal.org header.a=rsa-sha256 header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=il8mU81l; dkim=pass header.d=amazonses.com header.i= AT amazonses.com header.a=rsa-sha256 header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=RxhOUcCF; arc=fail smtp.remote-ip=140.211.10.49
- Arc-authentication-results: i=1; smtp4.osuosl.org; dmarc=pass header.from=drupal.org; dkim=pass header.d=drupal.org header.i= AT drupal.org header.a=rsa-sha256 header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=il8mU81l; dkim=pass header.d=amazonses.com header.i= AT amazonses.com header.a=rsa-sha256 header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=RxhOUcCF; arc=none smtp.remote-ip=54.240.27.34
- Arc-filter: OpenARC Filter v1.3.0 smtp4.osuosl.org 36803510A7
- Arc-filter: OpenARC Filter v1.3.0 smtp4.osuosl.org 49CF9405B3
- Arc-message-signature: i=2; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1790187529; h=X-Comment:DKIM-Signature:Received:X-Spam-Flag:X-Spam-Score: X-Spam-Level:X-Spam-Status:ARC-Filter:Received-SPF:DKIM-Signature: DKIM-Signature:Date:To:MIME-Version:Feedback-ID:X-Mailman-Rule-Hits: X-Mailman-Rule-Misses:Message-ID-Hash:X-Mailman-Approved-At: Message-ID:From:X-Mailman-Version:Precedence:Reply-To:Subject:List-Id: Archived-At:List-Archive:List-Help:List-Owner:List-Post: List-Subscribe:List-Unsubscribe:Content-Type: Content-Transfer-Encoding; bh=S13hh18mAHljWo9O9juxbgGpLLI7uRg8bIMrAB6b5D0=; b=ZHwzSZuB5dSL2QnRTat6kCr01ikvWQvGRQncCOtcha/tIL7sPvVoiH8Y9Wi3TpvV3aNM Z4tx/crPjvkWSUIEmraExqsBfh3+1mTHmRqftTX8yO18rXAfrl2yPIttiFK+pwyCltHVy kgpoHCMRFFSPmSoyT46wwRNTB3ycxxJReUPEbi3cIUP5dN0vYsOHM9JqbtNXjKfHfGZjM UDk2c8Mpsg6vLNDABRsSf4jKVgE2tdTx60mAhF+Woil2txU97VPMwrEX8QY6BUNKECLhn b1M4i3RBLwRqvwGr4IwBwqrJTH17TALlvYT0Yiqxrv+eM14qwhdfc3Q/cPqvo/+rP2Q==
- Arc-message-signature: i=1; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1790184275; h=Received-SPF:DKIM-Signature:DKIM-Signature:Date:Message-ID:To: Subject:X-PHP-Originating-Script:MIME-Version:Content-Type: Content-Transfer-Encoding:X-Mailer:Sender:From:Feedback-ID: X-SES-Outgoing; bh=AUydb8sTjzTOkrhLsAInBNyhwLCvbfdHLrIedq26v7s=; b=gkRw4l1u/KhtiGy2p1FH+oIMZmFsSYw7Sre5XXsfcRcXbnQAUzJCPOu23I1JyWIiEHra a6N+1kuPdL4wpuic4HTD/TXCbCVDo1E9qVuwSGuNUx8YjsV9g6mLfm/W9SNzY07wenQtl ni5Ev5KRy/FtI8ui/HPeKnmocr5FUNy6s0xNovZb/drYpvqtZshW4JP+N48x7qrFOkza2 bj44/dHH3lz8mdUu3e9z8ohJhUGzTNOW91nTjMlEIPo8RxFqhAYotO/NQwIsbCVWGh40H sh9RY3U51vHtjatutYj5lsfP3FnBwh6VCJpkjlMVYe7KycQo0y7oPO5bwffIXhFQ6ag==
- Arc-seal: i=2; d=osuosl.org; s=arc; a=rsa-sha256; cv=fail; t=1790187529; b=s68UGHMN+v1idyucAOlwv0KOawA6yFehg9CH98XKjpW602Z0L+NX/5BeBgemINmDsqai UwVNR15ZKpqXSrWt2V6XM38RlSsyQJBbl5Vysli7fNG0YxowKYr+xaeTQX8bg4mhAs32l RPzyOH4MFzeWPAw8l9NKG3P37E4FgKw95EaDlTjNU/DSZnAIY2BYCjQIlCYWUaS91v1gb 7OO5mQGpE4cB8IFq+yFWmKcXlvmMxh0nx+c1B4WSXt1LzT0tjgk/+onIm5CtSrmlXduKO ekMxggY1UcBsklycjg7tEPEa+SJHRNhOLn7hD8xp5DWuVm1KMF3cD+f41sKtjetC1zg==
- Arc-seal: i=1; d=osuosl.org; s=arc; a=rsa-sha256; cv=none; t=1790184275; b=QEEqvhNlw1WAZc/IAYfWe0PV9cp3vFMfp6j3Uj4puoaDOA7LO8rhDGSKS6wY/AgjGcxr RsR1CtcmGNLxtwCPklwkq0EyPxUasmNX3hcbKbxqiUCNuS8n1T/bFpTB0BYL9R0yDR+cP miIJ14tG3+lwWSlABgHRinKFC+7RICyijAcJPuXRCmZRPKGEGOX9+zp3AohvHwnKszget HFZyNl1jUHFMsAVj9fZrbnHdkCANoe530he8bjazF2tR3ZdW3gRIfC9H9XwWE9MEbdesi huv8tpwcukoleyrpFJlLQqO4yvuQuC/FVV07KpjSl7b/Nfw3sUToFKUs3K7ZxdT2fKA==
- Archived-at: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/message/OVXMOSRP4TFBO4YWLGAYGGIOROOAWUPL/>
- Authentication-results: lists.piratenpartei.de; dkim=pass header.d=drupal.org header.s=default header.b=Rb21JCdA; dkim=fail ("body hash did not verify") header.d=drupal.org header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=il8mU81l; dkim=fail ("body hash did not verify") header.d=amazonses.com header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=RxhOUcCF; spf=pass (lists.piratenpartei.de: domain of security-news-bounces AT drupal.org designates 140.211.166.137 as permitted sender) smtp.mailfrom=security-news-bounces AT drupal.org; arc=reject ("cv is fail on i=2"); dmarc=pass (policy=none) header.from=drupal.org
- Feedback-id: ::1.us-west-2.eaokZ1GT8utLqfMHQoyOsEFVrSIzzS6R+14LP6WIIUY=:AmazonSES
- List-archive: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/>
- List-id: <security-news.drupal.org>
View online: https://www.drupal.org/sa-contrib-2026-191
Project: Diba carousel slider [1]
Project machine name: diba_carousel
Date: 2026-September-23
Security risk: *Moderately critical* 12 ∕ 25
AC:Basic/A:User/CI:Some/II:Some/E:Theoretical/TD:Uncommon [2]
Vulnerability: Cross Site Scripting (XSS)
Affected versions: <3.0.2
CVE IDs: CVE-2026-96382
Description:
The Diba Carousel Slider adds a Bootstrap carousel slider block that can be
used directly without creating a View or custom integration.
When the "Allow HTML description" option is enabled, slide descriptions are
rendered using the raw stored field value instead of the field's rendered
output. This bypasses Drupal's text format filtering and output sanitization
mechanisms.
This vulnerability affects sites that use a formatted text field as the
carousel description source and have enabled the "Allow HTML description"
option.
Solution:
Upgrade to the latest version:
* If you are using Diba carousel slider 3.1.x, upgrade to Diba carousel
slider 3.1.1. [3]
* If you are using Diba carousel slider 3.0.x, upgrade to Diba carousel
slider 3.0.2. [4]
If you are unable to upgrade immediately, disable the "Allow HTML
description" option in affected carousel blocks until the update can be
applied.
Reported By:
* Kalle Kipinä (kekkis) [5]
Fixed By:
* Oriol Roselló Castells (oriol_e9g) [6]
Coordinated By:
* Swan Kalata (akalata) [7] of the Drupal Security Team
* Juraj Nemec (poker10) [8] of the Drupal Security Team
------------------------------------------------------------------------------
Contribution record [9]
[1] https://www.drupal.org/project/diba_carousel
[2] https://www.drupal.org/security-team/risk-levels
[3] https://www.drupal.org/project/diba_carousel/releases/3.1.1
[4] https://www.drupal.org/project/diba_carousel/releases/3.0.2
[5] https://www.drupal.org/u/kekkis
[6] https://www.drupal.org/u/oriol_e9g
[7] https://www.drupal.org/u/akalata
[8] https://www.drupal.org/u/poker10
[9] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal.org/node/3623987
_______________________________________________
Security-news mailing list -- security-news AT drupal.org
To unsubscribe send an email to security-news-leave AT drupal.org
Unsubscribe at
- [IT-SecNots] [Security-news] Diba carousel slider - Moderately critical - Cross Site Scripting (XSS) - SA-CONTRIB-2026-191, security-news, 23.09.2026
Archiv bereitgestellt durch MHonArc 2.6.19+.