CVE-2013-7064
Publication date 29 April 2014
Last updated 24 July 2024
Ubuntu priority
Cross-site scripting (XSS) vulnerability in the EU Cookie Compliance module 7.x-1.x before 7.x-1.12 for Drupal allows remote authenticated administrators with the "Administer EU Cookie Compliance popup" permission to inject arbitrary web script or HTML via unspecified configuration values.
Status
Package | Ubuntu Release | Status |
---|---|---|
drupal6 | ||
16.04 LTS xenial | Not in release | |
14.04 LTS trusty | Not in release | |
drupal7 | ||
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty |
Not affected
|
|
Notes
leosilva
module specific "Drupal core is not affected. If you do not use the contributed EU Cookie Compliance module, there is nothing you need to do."