Cross-Site Scripting Vulnerability in Drupal COOKiES Consent Management
CVE-2025-47703

6.1MEDIUM

Key Information:

Vendor

Drupal

Vendor
CVE Published:
14 May 2025

What is CVE-2025-47703?

A Cross-Site Scripting (XSS) vulnerability exists in the COOKiES Consent Management module for Drupal, specifically affecting versions prior to 1.2.14. This flaw arises from improper validation of user input during web page generation, allowing attackers to inject malicious scripts. Such exploitation can lead to unauthorized actions taking place on behalf of users, potentially compromising sensitive data and user interactions. It is imperative for site administrators using the affected versions to implement updates promptly to mitigate these vulnerabilities and safeguard against potential exploitation.

Affected Version(s)

COOKiES Consent Management 0.0.0 < 1.2.14

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Pierre Rudloff (prudloff)
Joachim Feltkamp (jfeltkamp)
Greg Knaddison (greggles)
Juraj Nemec (poker10)
.