Junglewise Threat Intelligence

CVE-2023-3620: tarteaucitron.js stored cross-site scripting in attribute handling

CVE-2023-3620 · Severity: low · CVSS 3 · Published 2023-07-11

Technologies: tarteaucitronjs (npm), Tarteaucitron.Js. Vendors: npm.

Executive brief

tarteaucitron.js is a JavaScript library used to manage cookie consent and privacy notices on websites. An attacker with stored data access (such as via an admin panel) can inject malicious JavaScript that executes in the browsers of all website visitors, potentially stealing session cookies, credentials, or redirecting users to phishing sites.

Technical details

This is a stored cross-site scripting (XSS) vulnerability in the tarteaucitron.js library prior to version 1.13.1, arising from improper sanitization of HTML attributes. The vulnerable code reads element attributes without adequate filtering, allowing attackers to inject arbitrary JavaScript. An attacker must be able to control stored data (such as cookie consent configuration) that the library processes. The fix filters attributes to prevent XSS payload injection. Users should upgrade to v1.13.1 or later.

Affected products

  • tarteaucitron tarteaucitron.js prior to 1.13.1

Timeline

  • 2023-07-11: disclosed
  • 2023-07-11: patched: v1.13.1 released with fix

References

Related threats