—
DRUPAL-CONTRIB-2023-017
Details
The Consent Popup provides a configurable popup that requires acceptance of a question before the visitor can continue, typically used for age consent.
The module doesn't sufficiently sanitizes the text on the block leading to a cross site scripting (XSS) vulnerability.
This vulnerability is mitigated by the fact that an attacker must have a role with the permission to create blocks.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist:https://packages.drupal.org/8/drupal/consent_popup
Introduced in:
0Fixed in: 1.0.3Upgrade drupal/consent_popup to 1.0.3 or newer (ecosystem packagist:https://packages.drupal.org/8).