CVE-2025-7392: Cookies Addons - Moderately critical - Cross-site Scripting - SA-CONTRIB-2025-087
Published Jul 21, 2025
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Cookies Addons allows Cross-Site Scripting (XSS).This issue affects Cookies Addons: from 1.0.0 before 1.2.4.
Affected Software
2 affected components
Drupal Cookies Addons>1.0.0<=1.2.4
Cookies Addons Project Cookies Addons Drupal>=1.0.0<1.2.4
Event History
Jul 21, 2025
CVE Published
via MITRE·04:36 PM
Data Sourced
via MITRE·04:36 PM
DescriptionWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-7392?
CVE-2025-7392 has a medium severity rating due to its potential for Cross-Site Scripting (XSS) exploitation.
2
How do I fix CVE-2025-7392?
To fix CVE-2025-7392, update the Drupal Cookies Addons to version 1.2.4 or later.
3
What versions are affected by CVE-2025-7392?
CVE-2025-7392 affects Drupal Cookies Addons versions from 1.0.0 up to, but not including, 1.2.4.
4
What type of vulnerability is CVE-2025-7392?
CVE-2025-7392 is an Improper Neutralization of Input During Web Page Generation vulnerability, categorized as Cross-Site Scripting (XSS).
5
Is CVE-2025-7392 actively being exploited?
As of now, there are no confirmed reports of active exploitation of CVE-2025-7392.