Executive brief
The Webform module for Drupal allows site administrators to build online forms and manage submissions. An insufficient sanitization flaw in the color element could allow an attacker who has placed a specially crafted link on the same page to inject malicious scripts, potentially compromising visitors' sessions or stealing sensitive form data.
Technical details
The vulnerability is a DOM-based or reflected XSS in the color element's attribute rendering due to inadequate sanitization. An attacker must be able to place a specially crafted link with a specific class on the same page as the webform to trigger the vulnerability. The issue affects versions before 6.2.12 and 6.3.0 through 6.3.0, with fixes available in 6.2.12 and 6.3.1.
Affected products
- Drupal Webform <6.2.12 or >=6.3.0 <6.3.1
Timeline
- 2026-09-23: disclosed
- 2026-09-23: patched: 6.2.12 and 6.3.1 releases