CVE-2025-47703: COOKiES Consent Management - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-049
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal COOKiES Consent Management allows Cross-Site Scripting (XSS).This issue affects COOKiES Consent Management: from 0.0.0 before 1.2.14.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47703?
CVE-2025-47703 has been assessed as a medium severity vulnerability due to its potential for exploitation through Cross-Site Scripting (XSS).
How do I fix CVE-2025-47703?
To fix CVE-2025-47703, upgrade the Drupal COOKiES Consent Management module to version 1.2.14 or later.
What products are affected by CVE-2025-47703?
CVE-2025-47703 affects the Drupal COOKiES Consent Management module versions prior to 1.2.14.
What type of vulnerability is CVE-2025-47703?
CVE-2025-47703 is classified as a Cross-Site Scripting (XSS) vulnerability due to improper neutralization of input.
Can CVE-2025-47703 be exploited remotely?
Yes, CVE-2025-47703 can be exploited remotely if an attacker injects malicious scripts into web pages.