Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Cookies Addons allows Cross-Site Scripting (XSS).This issue affects Cookies Addons: from 1.0.0 before 1.2.4.
Problem types
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
1.0.0 (semver) before 1.2.4
Credits
Pierre Rudloff (prudloff)
Guido Schmitz (guido_s)
Kostia Bohach (_shy)
Greg Knaddison (greggles)
Pierre Rudloff (prudloff)
References
www.drupal.org/sa-contrib-2025-087