Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-747v-52c4-8vj8

Опубликовано: 09 апр. 2024
Источник: github
Github: Прошло ревью
CVSS3: 3.1

Описание

Contao: Unencoded insert tags in the frontend

Impact

It is possible to inject insert tags via the form generator if the submitted form data is output on the page in a specific way.

Patches

Update to Contao 4.13.40 or 5.3.4.

Workarounds

Do not output the submitted form data on the website.

References

https://contao.org/en/security-advisories/insert-tag-injection-via-the-form-generator

For more information

If you have any questions or comments about this advisory, open an issue in contao/contao.

Пакеты

Наименование

contao/core-bundle

composer
Затронутые версииВерсия исправления

>= 4.0.0, < 4.13.40

4.13.40

Наименование

contao/core-bundle

composer
Затронутые версииВерсия исправления

>= 5.0.0-RC1, < 5.3.4

5.3.4

EPSS

Процентиль: 76%
0.00961
Низкий

3.1 Low

CVSS3

Дефекты

CWE-74

Связанные уязвимости

CVSS3: 3.1
nvd
почти 2 года назад

Contao is an open source content management system. Starting in version 4.0.0 and prior to version 4.13.40 and 5.3.4, it is possible to inject insert tags in frontend forms if the output is structured in a very specific way. Contao versions 4.13.40 and 5.3.4 have a patch for this issue. As a workaround, do not output user data from frontend forms next to each other, always separate them by at least one character.

EPSS

Процентиль: 76%
0.00961
Низкий

3.1 Low

CVSS3

Дефекты

CWE-74