CVE-2024-47069
CVSS V2 None
CVSS V3 None
Description
Oveleon Cookie Bar is a cookie bar is for the Contao Open Source CMS and allows a visitor to define cookie & privacy settings for the website. Prior to versions 1.16.3 and 2.1.3, the `block/locale` endpoint does not properly sanitize the user-controlled `locale` input before including it in the backend's HTTP response, thereby causing reflected cross-site scripting. Versions 1.16.3 and 2.1.3 contain a patch for the vulnerability.
Overview
- CVE ID
- CVE-2024-47069
- Assigner
- GitHub_M
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-09-23T15:30:02.984Z
- Last Modified Date
- 2024-09-23T16:09:53.133Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://github.com/oveleon/contao-cookiebar/security/advisories/GHSA-296q-rj83-g9rq | x_refsource_CONFIRM |
https://github.com/oveleon/contao-cookiebar/commit/1d57470be5878f66d5e1e23f624dd387564b9b8d | x_refsource_MISC |
https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html | x_refsource_MISC |
https://github.com/oveleon/contao-cookiebar/blob/2.x/src/Controller/CookiebarController.php | x_refsource_MISC |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-47069 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-47069 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-10-06 09:50:46 | Added to TrackCVE |