- GDPR cookies versions prior to 1.x-1.3.4
The GDPR cookies module enables sites to comply with the European cookie law using tarteaucitron.js.
The module doesn't sufficiently filter user-supplied markup inside of content leading to a persistent Cross Site Scripting (XSS) vulnerability.
This vulnerability is mitigated by the fact that an attacker must have permission to insert specific data attributes.
Upgrade your site to the most recent version of GDPR Cookies module.
- Martin Price Backdrop CMS maintainer
- Jen Lampton of the Backdrop CMS Security Team