Date: 
Thursday, Feb 6th, 2025
Advisory ID: 
BACKDROP-SA-CONTRIB-2025-001
Security risk: 
Moderately Critical
Vulnerability: 
Cross Site Scripting
Versions affected: 
  • Google Tag module 1.x-1.x versions prior to 1.x-1.6.2.
Description: 

This module enables you to integrate the site with the Google Tag Manager (GTM) application.

The module doesn't have the "restrict access" flag on the "administer google_tag_container" permission. A user with this permission can load a GTM container that completely changes the page or inserts malicious JS, resulting in a cross site scripting vulnerability.

This vulnerability is mitigated by the fact that an attacker must have a role with the aforementioned permission.

Solution: 

Upgrade your site to the most recent version of Google Tag manager. Download available on the Google Tag Manager module page

Reported By: 
Coordinated By: 

Security email list

Backdrop maintains a security mailing list. Whenever a security release comes out, an email will be sent to everyone subscribed to that list, announcing the new release. Please follow the steps below to join the Security email list.

  1. Log in to backdropcms.org
  2. Edit your profile
  3. Switch to the "Subscriptions" tab
  4. Check the box labeled "Security updates"
  5. Save the form