The Colorbox module 7.x-2.x before 7.x-2.10 for Drupal allows remote authenticated users with certain permissions to bypass intended access restrictions and "add unexpected content to a Colorbox" via unspecified vectors, possibly related to a link in a comment.
| Software | From | Fixed in |
|---|---|---|
| colorbox_project / colorbox | 7.x-2.3 | 7.x-2.3.x |
| colorbox_project / colorbox | 7.x-2.7 | 7.x-2.7.x |
| colorbox_project / colorbox | 7.x-2.2 | 7.x-2.2.x |
| colorbox_project / colorbox | 7.x-2.4 | 7.x-2.4.x |
| colorbox_project / colorbox | 7.x-2.8 | 7.x-2.8.x |
| colorbox_project / colorbox | 7.x-2.1 | 7.x-2.1.x |
| colorbox_project / colorbox | 7.x-2.9 | 7.x-2.9.x |
| colorbox_project / colorbox | 7.x-2.6 | 7.x-2.6.x |
| colorbox_project / colorbox | 7.x-2.5 | 7.x-2.5.x |
| colorbox_project / colorbox | 7.x-2.0 | 7.x-2.0.x |