6.5

CVE-2023-36806

Exploit

Contao cross site scripting vulnerability via input unit widget

Contao is an open source content management system. Starting in version 4.0.0 and prior to versions 4.9.42, 4.13.28, and 5.1.10, it is possible for untrusted backend users to inject malicious code into headline fields in the back end, which will be executed both in the element preview (back end) and on the website (front end). Installations are only affected if there are untrusted back end users who have the rights to modify headline fields, or other fields using the input unit widget. Contao 4.9.42, 4.13.28, and 5.1.10 have a patch for this issue. As a workaround, disable the login for all untrusted back end users.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ContaoContao Version >= 4.0.0 < 4.9.42
ContaoContao Version >= 4.10.0 < 4.13.28
ContaoContao Version >= 5.0.0 < 5.1.10
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.53% 0.408
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.4 2.3 2.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
security-advisories@github.com 6.5 2.3 3.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

https://github.com/contao/contao/commit/5c9aff32cfc1f7dc452a045862ac2f86a6b9b4b4
Patch
https://github.com/contao/contao/commit/c98585d36baa25fda69c062421e7e7eadc53c82b
Patch
https://github.com/contao/contao/commit/ccb64c777eb0f9c0e6490c9135d80e915d37cd32
Patch
https://github.com/contao/contao/security/advisories/GHSA-4gpr-p634-922x
Vendor Advisory
https://herolab.usd.de/security-advisories/usd-2023-0020/
Third Party Advisory
Exploit