What the vulnerability does
01Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dourou Cookie Warning allows Stored XSS. This issue affects Cookie Warning: from n/a through 1.3.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dourou Cookie Warning allows Stored XSS. This issue affects Cookie Warning: from n/a through 1.3.
Explanation of Vulnerability in Simple Terms
Cookie Warning versions up to 1.3 contain a cross-site scripting (XSS) vulnerability that allows authenticated users with low privileges to inject malicious scripts. An attacker can craft input that executes in other users' browsers, potentially stealing session data or performing actions on their behalf. The vulnerability requires network access and some attack complexity but can compromise site confidentiality, integrity, and availability.
What an attacker can do
Inject and execute malicious JavaScript in other users' browsers to steal data or perform unauthorized actions.
Potential impact on your site
Authenticated users can inject scripts affecting other visitors; attackers may steal admin sessions or modify site content.
Conditions required to exploit
Attacker must have low-level authenticated access to the site; no user interaction required from victims.
Key dates
External resources
Related vulnerabilities