CVE-2025-5682: Klaro Cookie & Consent Management - Moderately critical - Cross-site Scripting - SA-CONTRIB-2025-080
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Klaro Cookie & Consent Management allows Cross-Site Scripting (XSS).This issue affects Klaro Cookie & Consent Management: from 0.0.0 before 3.0.7.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5682?
The severity of CVE-2025-5682 is classified as moderate due to its potential for Cross-Site Scripting (XSS) attacks.
How do I fix CVE-2025-5682?
To fix CVE-2025-5682, update the Klaro Cookie & Consent Management module to version 3.0.7 or later.
What versions are affected by CVE-2025-5682?
CVE-2025-5682 affects Klaro Cookie & Consent Management versions from 0.0.0 up to, but not including 3.0.7.
What is Cross-Site Scripting in the context of CVE-2025-5682?
Cross-Site Scripting in the context of CVE-2025-5682 refers to a vulnerability where an attacker can inject malicious scripts into web pages viewed by users.
Are there any known exploits related to CVE-2025-5682?
Currently, there are no specific public exploits documented for CVE-2025-5682, but the XSS vulnerability can be leveraged in various attack scenarios.