DRUPAL-CONTRIB-2025-072

See a problem?
Import Source
https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/eu_cookie_compliance/DRUPAL-CONTRIB-2025-072.json
JSON Data
https://api.osv.dev/v1/vulns/DRUPAL-CONTRIB-2025-072
Aliases
  • CVE-2025-48917
Published
2025-05-28T17:43:44Z
Modified
2025-12-10T23:41:27.475514Z
Summary
[none]
Details

This module addresses the General Data Protection Regulation (GDPR) and the EU Directive on Privacy and Electronic Communications.

The module doesn't sufficiently verify whether "disabled JavaScript" entries are valid or correspond to actual scripts on the page. As a result, an attacker could inject and execute arbitrary JavaScript by adding invalid or non-existent entries, which the module then attempts to process.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission "Administer EU Cookie Compliance banner".

References
Credits

Affected packages

Packagist:https://packages.drupal.org/8 / drupal/eu_cookie_compliance

Package

Name
drupal/eu_cookie_compliance
Purl
pkg:composer/drupal/eu_cookie_compliance

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.26.0
Database specific
{
    "constraint": "<1.26.0"
}

Database specific

source
"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/eu_cookie_compliance/DRUPAL-CONTRIB-2025-072.json"
affected_versions
"<1.26.0"