Date: 
2023-August-02
Vulnerability: 
Cross Site Scripting
Affected versions: 
<1.22.0
Description: 

This module enables you to add the Matomo web statistics tracking system to your website.

The module does not check the Matomo JS code loaded on the website. So a user could configure the module to load JS from a malicious website.

This vulnerability is mitigated by the fact that an attacker must have a role with the permission "administer matomo" or "administer matomo tag manager" (D8+ only) to access the settings forms where this can be configured.

Solution: 

Install the latest version:

Sites are encouraged to review which roles have that permission and which users have that role, to ensure that only trusted users have that permission.

Reported By: 
Fixed By: 
Coordinated By: