gdpr_alertThis module enables you to define configurable GDPR alert messages.
The module doesn't sufficiently filter user-supplied text leading to a Cross Site Scripting (XSS) vulnerability.
This vulnerability is mitigated by the fact that an attacker needs additional permissions. The vulnerability can be exploited by an attacker with a role with the permission "administer gdpr alert" regardless of other configurations.
Install the latest version:
- If you use the GDPR alert module 1.0.0, upgrade to GDPR alert 1.0.1
- Damien McKenna of the Drupal Security Team
- Greg Knaddison of the Drupal Security Team