CVE-2024-47069

Oveleon Cookie Bar is a cookie bar is for the Contao Open Source CMS and allows a visitor to define cookie & privacy settings for the website. Prior to versions 1.16.3 and 2.1.3, the `block/locale` endpoint does not properly sanitize the user-controlled `locale` input before including it in the backend's HTTP response, thereby causing reflected cross-site scripting. Versions 1.16.3 and 2.1.3 contain a patch for the vulnerability.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:oveleon:cookiebar:*:*:*:*:*:cantao:*:*
cpe:2.3:a:oveleon:cookiebar:*:*:*:*:*:cantao:*:*

History

No history.

Information

Published : 2024-09-23 16:15

Updated : 2024-09-30 13:40


NVD link : CVE-2024-47069

Mitre link : CVE-2024-47069

CVE.ORG link : CVE-2024-47069


JSON object : View

Products Affected

oveleon

  • cookiebar
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')