- GDPR cookies module, 1.x versions prior to 1.x-1.3.3.
The GDPR cookies module contains a library with known vulnerabilities:
- https://security.snyk.io/vuln/SNYK-JS-TARTEAUCITRONJS-5772112
- https://security.snyk.io/vuln/SNYK-JS-TARTEAUCITRONJS-8366541
tarteaucitronjs is a package that provides compliance to the European cookie law. Affected versions of this package are vulnerable to Cross-site Scripting (XSS) due to missing sanitization of the services attributes value, and improper user-input sanitization, via width
, theme
, controls
, img
and other attributes.
Upgrade your site to the most recent version of the GDPR cookies module. Download available on the GDPR cookies module page.
- Jen Lampton of the Backdrop CMS Security Team