{"id":"DRUPAL-CONTRIB-2025-049","details":"The COOKIES module protects users from executing JavaScript code provided by third parties, e.g., to display ads or track user data without consent.\n\nThe cookies\\_asset\\_injector module (a sub-module of the COOKiES module) also allows inline JavaScript to be included in consent management. However, this does not adequately check whether the provided JavaScript code originates from authorized users.\n\nA potential attacker would at least need permission to create and publish HTML (e.g. content or comments).","aliases":["CVE-2025-47703"],"modified":"2026-09-10T03:45:29.620363638Z","published":"2025-05-07T17:06:36Z","references":[{"type":"WEB","url":"https://www.drupal.org/sa-contrib-2025-049"}],"affected":[{"package":{"name":"drupal/cookies","ecosystem":"Packagist:https://packages.drupal.org/8","purl":"pkg:composer/drupal/cookies?repository_url=https:%2F%2Fpackages.drupal.org%2F8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.2.14"}],"database_specific":{"constraint":"\u003c1.2.14"}}],"database_specific":{"affected_versions":"\u003c1.2.14","source":"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/cookies/DRUPAL-CONTRIB-2025-049.json"}}],"schema_version":"1.9.0","credits":[{"name":"Pierre Rudloff (prudloff)","contact":["https://www.drupal.org/u/prudloff"]}]}