Description
Oveleon Cookie Bar is a cookie bar is for the Contao Open Source CMS and allows a visitor to define cookie & privacy settings for the website. Prior to versions 1.16.3 and 2.1.3, the `block/locale` endpoint does not properly sanitize the user-controlled `locale` input before including it in the backend's HTTP response, thereby causing reflected cross-site scripting. Versions 1.16.3 and 2.1.3 contain a patch for the vulnerability.
Published: 2024-09-23
Score: 6.1 Medium
EPSS: 1.1% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-2223 Oveleon Cookie Bar is a cookie bar is for the Contao Open Source CMS and allows a visitor to define cookie & privacy settings for the website. Prior to versions 1.16.3 and 2.1.3, the `block/locale` endpoint does not properly sanitize the user-controlled `locale` input before including it in the backend's HTTP response, thereby causing reflected cross-site scripting. Versions 1.16.3 and 2.1.3 contain a patch for the vulnerability.
Github GHSA Github GHSA GHSA-296q-rj83-g9rq Reflected Cross Site-Scripting (XSS) in Oveleon Cookiebar
History

Mon, 30 Sep 2024 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Oveleon cookiebar
CPEs cpe:2.3:a:oveleon:cookiebar:*:*:*:*:*:cantao:*:*
Vendors & Products Oveleon cookiebar

Mon, 23 Sep 2024 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Oveleon
Oveleon contao-cookiebar
CPEs cpe:2.3:a:oveleon:contao-cookiebar:*:*:*:*:*:*:*:*
Vendors & Products Oveleon
Oveleon contao-cookiebar
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 23 Sep 2024 15:45:00 +0000

Type Values Removed Values Added
Description Oveleon Cookie Bar is a cookie bar is for the Contao Open Source CMS and allows a visitor to define cookie & privacy settings for the website. Prior to versions 1.16.3 and 2.1.3, the `block/locale` endpoint does not properly sanitize the user-controlled `locale` input before including it in the backend's HTTP response, thereby causing reflected cross-site scripting. Versions 1.16.3 and 2.1.3 contain a patch for the vulnerability.
Title Oveleon Cookiebar reflected Cross-site Scripting vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Oveleon Contao-cookiebar Cookiebar
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-09-23T16:09:53.133Z

Reserved: 2024-09-17T17:42:37.029Z

Link: CVE-2024-47069

cve-icon Vulnrichment

Updated: 2024-09-23T16:08:43.331Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-23T16:15:07.160

Modified: 2024-09-30T13:40:36.460

Link: CVE-2024-47069

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses