CVE-2013-7064

low
Published 2014-04-29 · Modified 2026-05-06
CVSS v3
VIR risk
2.1

Description

Cross-site scripting (XSS) vulnerability in the EU Cookie Compliance module 7.x-1.x before 7.x-1.12 for Drupal allows remote authenticated administrators with the "Administer EU Cookie Compliance popup" permission to inject arbitrary web script or HTML via unspecified configuration values.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.

Application impact

VendorProductVersionsFixed
freelance-it-consultanteu_cookie_compliance{"endIncluding":"7.x-1.11"}
freelance-it-consultanteu_cookie_compliance7.x-1.0
freelance-it-consultanteu_cookie_compliance7.x-1.1
freelance-it-consultanteu_cookie_compliance7.x-1.2
freelance-it-consultanteu_cookie_compliance7.x-1.6
freelance-it-consultanteu_cookie_compliance7.x-1.7
freelance-it-consultanteu_cookie_compliance7.x-1.8
freelance-it-consultanteu_cookie_compliance7.x-1.9
freelance-it-consultanteu_cookie_compliance7.x-1.10
freelance-it-consultanteu_cookie_compliance7.x-1.x

References

CWEs

CWE-79

💬 Discuss CVE-2013-7064 on VIR Community →

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.