GDPR cookies - Less critical - Cross Site Scripting - BACKDROP-SA-CONTRIB-2025-002
The GDPR cookies module contains a library with known vulnerabilities:
- https://security.snyk.io/vuln/SNYK-JS-TARTEAUCITRONJS-5772112
- https://security.snyk.io/vuln/SNYK-JS-TARTEAUCITRONJS-8366541
tarteaucitronjs is a package that provides compliance to the European cookie law. Affected versions of this package are vulnerable to Cross-site Scripting (XSS) due to missing sanitization of the services attributes value, and improper user-input sanitization, via width, theme, controls, img and other attributes.
- GDPR cookies module, 1.x versions prior to 1.x-1.3.3.
