AmauriC tarteaucitron.js
cpe:2.3:a:tarteaucitron.js_-_cookies_legislation_&_gdpr_project:tarteaucitron.js_-_cookies_legislation_&_gdpr:*:*:*:*:wordpress:*:*
- < 1.20.1
A vulnerability in tarteaucitron.js cookie banner prior to version 1.20.1 allows for improper validation of user-controlled width and height inputs. This flaw enables an attacker with high privileges to inject CSS that could cover the entire viewport, potentially leading to clickjacking attacks. The vulnerability could be exploited by overlaying malicious UI elements on top of legitimate content, tricking users into interacting with hidden elements, or disrupting the website's functionality and accessibility.
Exploitation of this vulnerability could allow for clickjacking attacks, where users are deceived into interacting with concealed elements, potentially leading to unintended actions on the website.
Users can update to tarteaucitron.js version 1.20.1 or later, where this vulnerability has been fixed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.