XSS Vulnerability in Tarteaucitron Cookie Banner by AmauriC
CVE-2025-31476

4.8MEDIUM

Key Information:

Vendor

Amauric

Vendor
CVE Published:
7 April 2025

What is CVE-2025-31476?

A cross-site scripting vulnerability was found in tarteaucitron.js, a cookie banner solution that ensures compliance and accessibility. This flaw allowed users with high privileges to inject links with insecure schemes, such as 'javascript:alert()'. The inadequate validation of URLs could lead to arbitrary JavaScript execution. Consequently, if a victim clicked on a maliciously crafted link, it could facilitate unauthorized access, the theft of sensitive data via phishing tactics, or manipulation of the site's user interface. The vulnerability has been addressed in version 1.20.1.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

tarteaucitron.js < 1.20.1

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.