PT-2025-2104 · Unknown · Cookiebot + Gtm
Cathy Theys
+3
·
Published
2024-10-30
·
Updated
2025-09-02
·
CVE-2024-13289
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Cookiebot + GTM versions 0.0.0 through 1.0.17
Description
The issue is related to improper neutralization of input during web page generation, also known as Cross-site Scripting (XSS). This allows an attacker to conduct Cross-Site Scripting attacks. The vulnerability is associated with the failure to protect the structure of web pages.
Recommendations
For versions 0.0.0 through 1.0.17, update to version 1.0.18 or later to resolve the issue. As a temporary workaround, consider restricting access to vulnerable components until a patch is available. Avoid using potentially vulnerable API endpoints or parameters that may be susceptible to Cross-Site Scripting attacks until the issue is resolved.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cookiebot + Gtm