Date: 
2023-June-21
Vulnerability: 
Cross Site Scripting
Affected versions: 
<4.4.13
Description: 

CivicCookieControl is a module that can help make a website compliant with EU and UK cookie legislation.

The Civic GovUK Cookie Control module does not sufficiently sanitize the configuration resulting in a Cross-Site Scripting (XSS) vulnerability.

This vulnerability is mitigated by the fact that the attacker must have a role with the "Administer Civic Cookie Control" permission.

Solution: 

Install the latest version:

Reported By: 
Coordinated By: