Description
The GDPR cookies module for Backdrop CMS (before
1.x-1.3.5) doesn't sufficiently protect visitors from Cross Site Scripting (XSS) if a malicious value has been provided for the optional 'Info content' field for the YouTube service. This is mitigated by the fact that an attacker must have a role with the permission "Create a GDPR Cookies Service" or "Edit any GDPR Cookies Service" and a site must have added a YouTube service as configuration.
1.x-1.3.5) doesn't sufficiently protect visitors from Cross Site Scripting (XSS) if a malicious value has been provided for the optional 'Info content' field for the YouTube service. This is mitigated by the fact that an attacker must have a role with the permission "Create a GDPR Cookies Service" or "Edit any GDPR Cookies Service" and a site must have added a YouTube service as configuration.
No analysis available yet.
Remediation
Vendor Solution
Upgrade to the latest release of the GDPR Cookies module.
Vendor Workaround
Remove the permission "Create a GDPR Cookies Service" or "Edit any GDPR Cookies Service", from all roles, or remove the YouTube service as configuration.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
| Link | Providers |
|---|---|
| https://backdropcms.org/security/sa-contrib-2025-013 |
|
History
Tue, 26 May 2026 01:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The GDPR cookies module for Backdrop CMS (before 1.x-1.3.5) doesn't sufficiently protect visitors from Cross Site Scripting (XSS) if a malicious value has been provided for the optional 'Info content' field for the YouTube service. This is mitigated by the fact that an attacker must have a role with the permission "Create a GDPR Cookies Service" or "Edit any GDPR Cookies Service" and a site must have added a YouTube service as configuration. | |
| Weaknesses | CWE-80 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-05-26T01:06:55.755Z
Reserved: 2026-05-26T01:06:55.112Z
Link: CVE-2025-71310
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses