[CIVN-2025-0169] Cross-site Scripting Vulnerability in COOKiES Consent Management module of Drupal

By Published On: August 11, 2025

—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Cross-site Scripting Vulnerability in COOKiES Consent Management module of Drupal 
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: CRITICAL
Software Affected
COOKiES Consent Management module of Drupal prior to 1.2.16
Overview
A vulnerability has been reported in COOKiES Consent Management module of Drupal which could be exploited by an attacker to perform cross-site scripting (XSS) attack on the targeted system.
Target Audience:
All website administrators and developers using COOKiES Consent Management Module of Drupal.
 
Risk Assessment:
High risk of system compromise.
Impact Assessment:
Potential for data breaches, execution of arbitrary scripts, malicious redirects or defacement.
Description
Drupal is an open-source content management system (CMS) which allows businesses, individuals and organisations to create, manage, and maintain websites and web applications.
This vulnerability exists within COOKiES Consent Management Systems due to insufficient validation when converting the ‘data-src’ attributes to ‘src’. An attacker could exploit this vulnerability by executing malicious content on the HTML element.
Successful exploitation of this vulnerability could allow the attacker to conduct cross-site scripting (XSS) attacks on the target system.
Solution
Apply appropriate updates as mentioned by the vendor:
https://www.drupal.org/sa-contrib-2025-092
Vendor Information
Drupal
https://www.drupal.org/sa-contrib-2025-092
References
Drupal
https://www.drupal.org/sa-contrib-2025-092
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmiaAKcACgkQ3jCgcSdc
ys+3zw//WTuj5u80qFFQFoLUJ1Y9Ac3yTGti8SbYSiwZJGQqVstqwBLvk7FsC9ai
NEdy5geQoxwqcoHqCSEg16lYKsXN+N7/wFXbiC0YFfnPBJwkEmUFKA95XudkaTo2
omtDdWEBVD0iNBRQ9PKzUnZheHNFA3uye74Ct7/NgqS5gY9d75zdhZHD1J6OeZ8Q
b/FtKggl5DW+8R/Xu1Jm/80S90n10jof7DDzeY3hiIxhuB/LJTExKMEgEZhyt2Nh
d+pfURM4mNWyP5QokuPoOyiRHUxHm1bmWEn8pOMB9gzJKO0uDKPua8JTXZp+XWOz
mj6c6lIPLgPtfXtlAcGAD/Roy5c0BZM+2jV3y9g3Wn6RcE0wBnU+fhSbSy5Basff
B3wB/2S6YEKucOmGgOCozFM9wAJYG4KFbiTh+auDPj5Lj5aeQYTFVX7rhurxdwWA
kdTBQ21nEnk1ebTdFnVNqeyeh5rveHCnrzng5dwThmie+jVlKuSwNKhhl0C9IYuO
9nv40gMFy9mzf8W5Ip6mDuandawCGfZQE9b0rRFazd7i/t6+X2E047Zn1PhEsMb0
nWEkdxbDWEGx3QqxUZlUSUjR12zukHWkvSYOV9+eb6tcaICy4azo0+7ly+SkaCoN
3BPloySAvyPaPAxEbLJ069iSYaCkE2SAHcU53dXMsKtPTOxK670=
=BqDj
—–END PGP SIGNATURE—–

Share this article