Server side cross-site scripting In contao/core-bundle
Description
Cross site scripting via input unit widget
Impact
Authenticated users can inject malicious code in widgets with units, which is then executed both in the element preview (back end) and on the website (front end).
Patches
Update to Contao 4.9.42, 4.13.28 or 5.1.10.
Workarounds
Disable login for all untrusted back end users.
References
https://contao.org/en/security-advisories/cross-site-scripting-in-widgets-with-units
For more information
If you have any questions or comments about this advisory, open an issue in contao/contao.
Credits
Thanks to Christian Pöschl and Fabian Brenner from usd AG for reporting this vulnerability.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
packagist | 4.9.42, 4.13.28, 5.1.10 |
Aliases
References