{"id":"DRUPAL-CONTRIB-2025-012","details":"This module enables you to integrate the site with the Google Tag Manager (GTM) application.\n\nThe module doesn't sufficiently validate the enabling or disabling of a tag container. The routes involved are not protected against Cross Site Request Forgery (CSRF).\n\nThis vulnerability is mitigated by the fact that an attacker needs to know the machine name of the container. The machine name is a random string, making an attack more difficult.","aliases":["CVE-2025-31683","GHSA-qchr-8m24-7v66"],"modified":"2026-09-10T03:45:54.597048249Z","published":"2025-01-29T17:16:19Z","references":[{"type":"WEB","url":"https://www.drupal.org/sa-contrib-2025-012"}],"affected":[{"package":{"name":"drupal/google_tag","ecosystem":"Packagist:https://packages.drupal.org/8","purl":"pkg:composer/drupal/google_tag?repository_url=https:%2F%2Fpackages.drupal.org%2F8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.8.0"}],"database_specific":{"constraint":"\u003c1.8.0"}},{"type":"ECOSYSTEM","events":[{"introduced":"2.0.0"},{"fixed":"2.0.8"}],"database_specific":{"constraint":"\u003e=2.0.0 \u003c2.0.8"}}],"database_specific":{"affected_versions":"\u003c1.8.0 || \u003e=2.0.0 \u003c2.0.8","source":"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/google_tag/DRUPAL-CONTRIB-2025-012.json"}}],"schema_version":"1.9.0","credits":[{"name":"Florent Torregrosa","contact":["https://www.drupal.org/user/2388214"]},{"name":"Pierre Rudloff","contact":["https://www.drupal.org/user/3611858"]}]}