Cross-Site Scripting Vulnerability in Cookies Addons for Drupal
CVE-2025-7392

Currently unrated

Key Information:

Vendor

Drupal

Vendor
CVE Published:
21 July 2025

What is CVE-2025-7392?

The Cookies Addons for Drupal contains a vulnerability that allows for Cross-Site Scripting (XSS) attacks due to improper handling of input during web page generation. This flaw can enable attackers to inject malicious scripts, potentially leading to unauthorized actions executed in the context of the affected user's session. The vulnerability impacts versions from 1.0.0 up to, but not including, 1.2.4.

Affected Version(s)

Cookies Addons 1.0.0 < 1.2.4

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Pierre Rudloff (prudloff)
Guido Schmitz (guido_s)
Kostia Bohach (_shy)
Greg Knaddison (greggles)
Pierre Rudloff (prudloff)
.
CVE-2025-7392 : Cross-Site Scripting Vulnerability in Cookies Addons for Drupal