{"id":"DRUPAL-CONTRIB-2025-074","details":"The module adds the etracker web statistics tracking system to your website.\n\nThe cookies\\_etracker submodule allows the inline JavaScript to be included in consent management. However, this does not adequately check whether the provided JavaScript code originates from authorized users.\n\nA potential attacker would at least need permission to create and publish HTML (e.g. content or comments).","aliases":["CVE-2025-48920"],"modified":"2026-09-10T03:45:31.514508123Z","published":"2025-05-28T17:44:33Z","references":[{"type":"WEB","url":"https://www.drupal.org/sa-contrib-2025-074"}],"affected":[{"package":{"name":"drupal/etracker","ecosystem":"Packagist:https://packages.drupal.org/8","purl":"pkg:composer/drupal/etracker?repository_url=https:%2F%2Fpackages.drupal.org%2F8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.1.0"}],"database_specific":{"constraint":"\u003c3.1.0"}}],"database_specific":{"affected_versions":"\u003c3.1.0","source":"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/etracker/DRUPAL-CONTRIB-2025-074.json"}}],"schema_version":"1.9.0","credits":[{"name":"Pierre Rudloff (prudloff)","contact":["https://www.drupal.org/u/prudloff"]}]}