CVE Feed

    Dashboard / CVE / CVE-2024-47069

    CVE-2024-47069

    Oveleon Cookie Bar is a cookie bar is for the Contao Open Source CMS and allows a visitor to define cookie & privacy settings for the website. Prior to versions 1.16.3 and 2.1.3, the `block/locale` endpoint does not properly sanitize the user-controlled `locale` input before including it in the backend's HTTP response, thereby causing reflected cross-site scripting. Versions 1.16.3 and 2.1.3 contain a patch for the vulnerability.

    Published:Sep 23, 2024
    Last Modified:Sep 30, 2024
    EPS:Sep 23, 2024
    EPSS Score:0.00187
    CVSS Score:6.1

    Affected Products

    Vendor
    Oveleon
    Product
    Contao-cookiebar
    Vendor
    Oveleon
    Product
    Cookiebar

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High