Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j55w-hjpj-825g

Опубликовано: 09 апр. 2024
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

Contao: Insufficient BBCode sanitizer

Impact

If BBCode is enabled for comments, users can inject CSS styles.

Patches

Update to Contao 4.13.40 or 5.3.4.

Workarounds

Disable BBCode for comments.

References

https://contao.org/en/security-advisories/insufficient-bbcode-sanitization

For more information

If you have any questions or comments about this advisory, open an issue in contao/contao.

Пакеты

Наименование

contao/comments-bundle

composer
Затронутые версииВерсия исправления

>= 2.0.0, < 4.13.40

4.13.40

Наименование

contao/comments-bundle

composer
Затронутые версииВерсия исправления

>= 5.0.0-RC1, < 5.3.4

5.3.4

EPSS

Процентиль: 72%
0.00701
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-74

Связанные уязвимости

CVSS3: 4.3
nvd
почти 2 года назад

Contao is an open source content management system. Starting in version 2.0.0 and prior to versions 4.13.40 and 5.3.4, it is possible to inject CSS styles via BBCode in comments. Installations are only affected if BBCode is enabled. Contao versions 4.13.40 and 5.3.4 have a patch for this issue. As a workaround, disable BBCode for comments.

EPSS

Процентиль: 72%
0.00701
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-74