Date: 
2018-July-11
Vulnerability: 
Cross Site Scripting
Description: 

This module addresses the General Data Protection Regulation (GDPR) that came into effect 25th May 2018, and the EU Directive on Privacy and Electronic Communications from 2012. It provides a banner where you can gather consent from the user to store cookies on their computer and handle their personal information.

This module does not sanitize some inputs leading to XSS. This is mitigated by the attacker having the permission "Administer EU Cookie Compliance."

Solution: 

Install the latest version:

Also see the EU Cookie Compliance project page.

Reported By: 
Coordinated By: