← Back

CVE-2025-31476

nvd nist
Published: Apr 7, 2025Modified: Sep 4, 2025

JSON object

Loading...
4.8
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Exploitability: 1.7 / Impact: 2.7
Source: security-advisories@github.com (Secondary)

Description

tarteaucitron.js is a compliant and accessible cookie banner. A vulnerability was identified in tarteaucitron.js, allowing a user with high privileges (access to the site's source code or a CMS plugin) to enter a URL containing an insecure scheme such as javascript:alert(). Before the fix, URL validation was insufficient, which could allow arbitrary JavaScript execution if a user clicked on a malicious link. An attacker with high privileges could insert a link exploiting an insecure URL scheme, leading to execution of arbitrary JavaScript code, theft of sensitive data through phishing attacks, or modification of the user interface behavior. This vulnerability is fixed in 1.20.1.

Affected (2)

1 product
Tarteaucitronjs
1 product
Tacjs
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 1.20.1
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
From 8.x-1.0 to 8.x-6.7

References (3)

Source: security-advisories@github.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.