CyberRota
← Ana sayfaya dön

CVE-2025-71310

UNKNOWN · CVSS N/A EPSS %0.26

Kaynak: NVD + CISA KEV + EPSS · Yayınlanma: 2026-05-26T02:16:39.060 · Çekilme zamanı: 2026-06-20T12:03:55.323357+00:00

CyberRota Yorumu

Detaylı analiz gerekiyor.

CVE
CVE-2025-71310
Severity
UNKNOWN
CVSS
N/A
EPSS
%0.26

Orijinal NVD Açıklaması

The GDPR cookies module for Backdrop CMS (before 1.x-1.3.5) doesn't sufficiently protect visitors from Cross Site Scripting (XSS) if a malicious value has been provided for the optional 'Info content' field for the YouTube service. This is mitigated by the fact that an attacker must have a role with the permission "Create a GDPR Cookies Service" or "Edit any GDPR Cookies Service" and a site must have added a YouTube service as configuration.