CookieCuttr
An administrator account could save malicious scripts in the settings form which would then run on the site. They could read private session details and alter the cookie banner text. They could not do this without administrator access rights.
- Who could do thisOnly someone with an administrator login.
- Does it apply to youThis applies if an attacker has the access right to manage the cookie settings.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate CookieCuttr to 2.0.3.
For developers: what the fix changed
The fix applies Xss::filterAdmin to the configuration variables in the cookiecuttr_settings function within cookiecuttr.module to prevent cross site scripting.
Also in this release The release also updates the core version requirement to include Drupal 12.
cookiecuttr.info.yml+1 −1cookiecuttr.module+2 −1 fix