Install

Works with Drupal: 7.x

Using Composer to manage Drupal site dependencies

Downloads

Download eu_cookie_compliance-7.x-1.26.tar.gztar.gz 32.87 KB
MD5: f298bd00a01cada747d2599cacba5353
SHA-1: 3469c1d3bccfbd25e79e2984633e9095a1b1626f
SHA-256: c6d9ee4dd94bd22415ae54e598e1aeff4d0c4c90b9e63656697076e1225d2f5e
Download eu_cookie_compliance-7.x-1.26.zipzip 42.07 KB
MD5: 83f9edeff6bb73b3e62ea4bb2ee2759a
SHA-1: 9e6dce15f4fcb7a94971b46d1f6678adf2adcaed
SHA-256: 07bc380da435568ad91bbe7acdd134cf2f3edb2819b07de8cd8aaea1db0f9fe4

Release notes

Fixed a security issue where some output was not sanitized, causing potential XSS. The issue is mitigated by the attacker needing to have the permission "Administer EU Cookie Compliance". Also several bug fixes. See EU Cookie Compliance - Critical - Cross site scripting - SA-CONTRIB-2019-033.

Fix security issue involving XSS. Mitigated by need to have admin access
Issue #3002528 by svenryen: Withdraw consent after agreeing is not working correctly
Issue #3020156 by svenryen: drupalSettings wrongly used in withdrawAction function
Issue #3008618 by svenryen: attachBehaviors after loading blacklisted scripts
Issue #2999117 by Dakwamine: In opt-out mode, do not ask again the user if he wants to consent after a withdraw
Issue #2973700 by AdamPS, svenryen: Consent by clicking option to exclude pages
Issue #3007865 by qwertyllo, das-peter, mfernea: Javascript undefined error after file uploads / ajax calls
Issue #2985662 by COBadger, svenryen: Missing button
Issue #3013518 by tauno, svenryen: Use CloudFlare's CF-IPCountry as a fallback if available
Issue #3013166 by das-peter: rror: Using $this when not in object context in eu_cookie_compliance_admin_form()
Issue #3012020 by Leo Pitt, svenryen: Spaces between class attributes and "="
Issue #2985558 by EduardoMadrid, svenryen: Convert javascript uris like public://path/file.js to relative paths
Issue #2994592 by jcnventura, svenryen, artfulrobot: Deletes cookies every 5s
Issue #2985520 by jasa, jyraya: After updating the module, a warning message appears about undefined withdraw_message, consent_storage_method and disabled_javascripts indexes
Issue #3001177 by svenryen, deepanker_bhalla, denisveg: Coding standard
Issue #2985543 by leymannx, svenryen: Notice: Undefined variable: primary_button_label
Issue #2986882 by smokris: Key to json hash cannot be "class" as it is a reserved word, use of "let" is not supported by all browsers as is ECMAScript

Created by: svenryen
Created on: 6 Mar 2019 at 12:02 UTC
Last updated: 7 Mar 2019 at 18:28 UTC
Security update
Bug fixes

Other releases