These vulnerabilities are caused due to improper sanitization of certain unspecified input in Image and color module before being returned to the user in Drupal Core. A remote attacker could exploit these vulnerabilities to insert arbitrary HTML and script code.
Successful exploitation of these vulnerabilities could allow a remote attacker to conduct Cross-Site Scripting (XSS) attacks in context of an affected site.
The information provided herein is on "as is" basis, without warranty of any kind.