PT-2023-37021 · Packagist · Drupal/Matomo

Published

2023-08-02

·

Updated

2023-08-02

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
This module enables you to add the Matomo web statistics tracking system to your website.
The module does not check the Matomo JS code loaded on the website. So a user could configure the module to load JS from a malicious website.
This vulnerability is mitigated by the fact that an attacker must have a role with the permission "administer matomo" or "administer matomo tag manager" (D8+ only) to access the settings forms where this can be configured.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

DRUPAL-CONTRIB-2023-033

Affected Products

Drupal/Matomo