Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2223 | Oveleon Cookie Bar is a cookie bar is for the Contao Open Source CMS and allows a visitor to define cookie & privacy settings for the website. Prior to versions 1.16.3 and 2.1.3, the `block/locale` endpoint does not properly sanitize the user-controlled `locale` input before including it in the backend's HTTP response, thereby causing reflected cross-site scripting. Versions 1.16.3 and 2.1.3 contain a patch for the vulnerability. |
Github GHSA |
GHSA-296q-rj83-g9rq | Reflected Cross Site-Scripting (XSS) in Oveleon Cookiebar |
Mon, 30 Sep 2024 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Oveleon cookiebar
|
|
| CPEs | cpe:2.3:a:oveleon:cookiebar:*:*:*:*:*:cantao:*:* | |
| Vendors & Products |
Oveleon cookiebar
|
Mon, 23 Sep 2024 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Oveleon
Oveleon contao-cookiebar |
|
| CPEs | cpe:2.3:a:oveleon:contao-cookiebar:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Oveleon
Oveleon contao-cookiebar |
|
| Metrics |
ssvc
|
Mon, 23 Sep 2024 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Oveleon Cookie Bar is a cookie bar is for the Contao Open Source CMS and allows a visitor to define cookie & privacy settings for the website. Prior to versions 1.16.3 and 2.1.3, the `block/locale` endpoint does not properly sanitize the user-controlled `locale` input before including it in the backend's HTTP response, thereby causing reflected cross-site scripting. Versions 1.16.3 and 2.1.3 contain a patch for the vulnerability. | |
| Title | Oveleon Cookiebar reflected Cross-site Scripting vulnerability | |
| Weaknesses | CWE-79 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-09-23T16:09:53.133Z
Reserved: 2024-09-17T17:42:37.029Z
Link: CVE-2024-47069
Updated: 2024-09-23T16:08:43.331Z
Status : Analyzed
Published: 2024-09-23T16:15:07.160
Modified: 2024-09-30T13:40:36.460
Link: CVE-2024-47069
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA