Project: 
Date: 
2018-April-18
Vulnerability: 
Cross site scripting (XSS)
Description: 

Display Suite allows you to take full control over how your content is displayed using a drag and drop interface.

The module doesn't sufficiently validate view modes provided dynamically via URLs leading to a reflected cross site scripting (XSS) attack.

This vulnerability is mitigated only by the fact that most modern browsers protect against reflected XSS via the url.

Solution: 
Reported By: 
Fixed By: 
Coordinated By: