logo

Database

Inappropriate coding practices In contao/core-bundle

Description

Contao is vulnerable to cross-site scripting in templates

Impact

It is possible to inject code into the template output that will be executed in the browser in the front end and back end.

Patches

Update to Contao 4.13.57, 5.3.42 or 5.6.5.

Workarounds

Do not use the affected templates or patch them manually.

Refsources

https://contao.org/en/security-advisories/cross-site-scripting-in-templates

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions