CVE-2025-8362 Details
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal GoogleTag Manager allows Cross-Site Scripting (XSS).This issue affects GoogleTag Manager: from 0.0.0 before 1.10.0.
A cross-site scripting (XSS) vulnerability has been identified in the Drupal Google Tag Manager module, affecting versions prior to 1.10.0. The issue arises because the module does not properly sanitize the Google Tag Manager container ID input from users with the 'Administer gtm' permission. This unsanitized input is directly inserted into a script tag, creating an XSS vulnerability. The issue is compounded by the fact that the input field allows up to 20 characters, providing enough space for malicious payloads.
Users are advised to upgrade to Google Tag Manager version 8.x-1.10, which includes necessary input validation to prevent such injections. Additionally, site administrators should review the roles assigned the 'Administer gtm' permission.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 15, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.drupal.org/sa-contrib-2025-094 | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| googletag manager project googletag manager | < 1.10.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 21, 2025 | Initial Analysis | [email protected] |
| Aug 15, 2025 | New CVE Received | [email protected] |
| Aug 15, 2025 | CVE Modified | CISA-ADP |