Cross-site scripting (XSS) vulnerability in the EU Cookie Compliance module 7.x-1.x before 7.x-1.12 for Drupal allows remote authenticated administrators with the "Administer EU Cookie Compliance popup" permission to inject arbitrary web script or HTML via unspecified configuration values.
| Software | From | Fixed in |
|---|---|---|
| freelance-it-consultant / eu_cookie_compliance | 7.x-1.8 | 7.x-1.8.x |
| freelance-it-consultant / eu_cookie_compliance | - | 7.x-1.11.x |
| freelance-it-consultant / eu_cookie_compliance | 7.x-1.2 | 7.x-1.2.x |
| freelance-it-consultant / eu_cookie_compliance | 7.x-1.0 | 7.x-1.0.x |
| freelance-it-consultant / eu_cookie_compliance | 7.x-1.6 | 7.x-1.6.x |
| freelance-it-consultant / eu_cookie_compliance | 7.x-1.10 | 7.x-1.10.x |
| freelance-it-consultant / eu_cookie_compliance | 7.x-1.x-dev | 7.x-1.x-dev.x |
| freelance-it-consultant / eu_cookie_compliance | 7.x-1.9 | 7.x-1.9.x |
| freelance-it-consultant / eu_cookie_compliance | 7.x-1.1 | 7.x-1.1.x |
| freelance-it-consultant / eu_cookie_compliance | 7.x-1.7 | 7.x-1.7.x |