cve/2024/CVE-2024-47069.md
2025-09-29 16:08:36 +00:00

1.1 KiB

CVE-2024-47069

Description

Oveleon Cookie Bar is a cookie bar is for the Contao Open Source CMS and allows a visitor to define cookie & privacy settings for the website. Prior to versions 1.16.3 and 2.1.3, the block/locale endpoint does not properly sanitize the user-controlled locale input before including it in the backend's HTTP response, thereby causing reflected cross-site scripting. Versions 1.16.3 and 2.1.3 contain a patch for the vulnerability.

POC

Reference

Github

No PoCs found on GitHub currently.