CVE-2025-47704: Klaro Cookie & Consent Management - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-050
Published May 14, 2025
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Klaro Cookie & Consent Management allows Cross-Site Scripting (XSS).This issue affects Klaro Cookie & Consent Management: from 0.0.0 before 3.0.5.
Affected Software
3 affected components
Drupal Klaro Cookie & Consent Management>0.0.0, <=3.0.5
Klaro Cookie \& Consent Management Project Klaro Cookie \& Consent Management Drupal<3.0.5
Klaro Cookie \& Consent Management Project Klaro Cookie \& Consent Management Drupal>=7.x-1.0<=7.x-1.2
Event History
May 14, 2025
CVE Published
via MITRE·05:02 PM
Data Sourced
via MITRE·05:02 PM
DescriptionWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Sep 19, 57356
Event
via FIRST·02:39 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-47704?
CVE-2025-47704 has been classified as a high severity Cross-Site Scripting (XSS) vulnerability.
2
How do I fix CVE-2025-47704?
To fix CVE-2025-47704, you should update the Klaro Cookie & Consent Management module to version 3.0.5 or later.
3
Which versions of Klaro Cookie & Consent Management are affected by CVE-2025-47704?
CVE-2025-47704 affects Klaro Cookie & Consent Management versions from 0.0.0 up to 3.0.5.
4
What kind of attack can CVE-2025-47704 enable?
CVE-2025-47704 allows attackers to perform Cross-Site Scripting (XSS) attacks.
5
What can be compromised due to CVE-2025-47704?
Due to CVE-2025-47704, attackers can inject malicious scripts that may compromise user data or session information.