Project: 
Date: 
2023-May-31
Vulnerability: 
Cross Site Scripting
Affected versions: 
<1.0.3
Description: 

The Consent Popup provides a configurable popup that requires acceptance of a question before the visitor can continue, typically used for age consent.

The module doesn't sufficiently sanitizes the text on the block leading to a cross site scripting (XSS) vulnerability.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission to create blocks.

Solution: 

Install the latest version:

Reported By: 
Coordinated By: