PT-2023-37017 · Packagist · Drupal/Tacjs

Published

2023-06-28

·

Updated

2023-06-28

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
This module enables sites to comply with the European cookie law using tarteaucitron.js.
The module doesn't sufficiently filter user-supplied text leading to a Cross Site Scripting (XSS) vulnerability.
This vulnerability is mitigated by the fact that an attacker needs additional permissions. The vulnerability can be exploited by an attacker with a role with the permission "administer tacjs" regardless of other configurations.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

DRUPAL-CONTRIB-2023-029

Affected Products

Drupal/Tacjs