(#Several vulnerabilities have been identified in Drupal third-party modules:#- Block Class: cross-site scripting due to mishandle of class names. A remote attacker with the permission " Administer block classes" could exploit it by inciting their victim to open a specially crafted link in order to execute arbitrary Javacript/HTML code (CVE-2016-3144)##- Open Atrium: cross-site scripting due to mishandling of some user supplied text. A remote attacker could exploit it by inciting their victim to open a specially crafted link in order to execute arbitrary Javacript/HTML code##- Select2 Field Widget: cross-site scripting due to mishandling of some user supplied text. A remote attacker could exploit it by inciting their victim to open a specially crafted link in order to execute arbitrary Javacript/HTML code##- Values: arbitrary PHP code execution due to the use of "eval()" function over a not trusted exported PHP code. "import value sets" permissions are required in order to exploit this vulnerability.)