1.x-1.3.5) doesn't sufficiently protect visitors from Cross Site Scripting (XSS) if a malicious value has been provided for the optional 'Info content' field for the YouTube service. This is mitigated by the fact that an attacker must have a role with the permission "Create a GDPR Cookies Service" or "Edit any GDPR Cookies Service" and a site must have added a YouTube service as configuration.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade to the latest release of the GDPR Cookies module.
Vendor Workaround
Remove the permission "Create a GDPR Cookies Service" or "Edit any GDPR Cookies Service", from all roles, or remove the YouTube service as configuration.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://backdropcms.org/security/sa-contrib-2025-013 |
|
Tue, 26 May 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Backdropcms
Backdropcms gdpr Cookies Module For Backdrop Cms |
|
| Vendors & Products |
Backdropcms
Backdropcms gdpr Cookies Module For Backdrop Cms |
Tue, 26 May 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 26 May 2026 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Cross‑Site Scripting via YouTube Service Info Content in BackdropCMS GDPR Cookies Module |
Tue, 26 May 2026 01:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The GDPR cookies module for Backdrop CMS (before 1.x-1.3.5) doesn't sufficiently protect visitors from Cross Site Scripting (XSS) if a malicious value has been provided for the optional 'Info content' field for the YouTube service. This is mitigated by the fact that an attacker must have a role with the permission "Create a GDPR Cookies Service" or "Edit any GDPR Cookies Service" and a site must have added a YouTube service as configuration. | |
| Weaknesses | CWE-80 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-05-26T12:29:15.986Z
Reserved: 2026-05-26T01:06:55.112Z
Link: CVE-2025-71310
Updated: 2026-05-26T12:29:13.237Z
Status : Deferred
Published: 2026-05-26T02:16:39.060
Modified: 2026-06-17T10:04:03.123
Link: CVE-2025-71310
No data.
OpenCVE Enrichment
Updated: 2026-05-26T12:59:44Z