Project: 
Project machine name: 
gdpr_alert
Date: 
2023-June-28
Vulnerability: 
Cross Site Scripting
Affected versions: 
>=1.0 <1.0.1
Description: 

This module enables you to define configurable GDPR alert messages.

The module doesn't sufficiently filter user-supplied text leading to a Cross Site Scripting (XSS) vulnerability.

This vulnerability is mitigated by the fact that an attacker needs additional permissions. The vulnerability can be exploited by an attacker with a role with the permission "administer gdpr alert" regardless of other configurations.

Solution: 

Install the latest version:

Reported By: 
Coordinated By: