Junglewise Threat Intelligence

CVE-2025-71310: Backdrop CMS GDPR Cookies XSS in YouTube service configuration

CVE-2025-71310 · Severity: info · CVSS 1.8 · Published 2026-05-26

Executive brief

The GDPR Cookies module for Backdrop CMS, which helps websites manage user consent for third-party services, contains a security flaw. An attacker with administrative permissions could inject malicious scripts into the 'Info content' field of the YouTube service configuration. If exploited, this could allow the attacker to execute unauthorized actions in the browsers of other site visitors or administrators.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in the GDPR Cookies module for Backdrop CMS due to insufficient sanitization of the 'Info content' field within the YouTube service configuration. An attacker with high-level privileges (specifically the 'Create a GDPR Cookies Service' or 'Edit any GDPR Cookies Service' permissions) can inject malicious HTML or JavaScript. The vulnerability is triggered when the YouTube service is configured and a user views the affected content. This is mitigated by the requirement for specific administrative roles and the necessity of the YouTube service being active. The issue is resolved in version 1.x-1.3.5.

Affected products

  • Backdrop CMS GDPR Cookies module versions prior to 1.x-1.3.5

Timeline

  • 2025-05-06: advisory: Backdrop CMS security advisory SA-CONTRIB-2025-013 published
  • 2026-05-26: disclosed: CVE-2025-71310 published to NVD

References