CVE-2013-7064
Publication date 29 April 2014
Last updated 24 July 2024
Ubuntu priority
Description
Cross-site scripting (XSS) vulnerability in the EU Cookie Compliance module 7.x-1.x before 7.x-1.12 for Drupal allows remote authenticated administrators with the "Administer EU Cookie Compliance popup" permission to inject arbitrary web script or HTML via unspecified configuration values.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| drupal6 | ||
| drupal7 | ||
Notes
leosilva
module specific "Drupal core is not affected. If you do not use the contributed EU Cookie Compliance module, there is nothing you need to do."