Cross-site scripting (XSS) vulnerability in system/modules/comments/Comments.php in Contao CMS 2.9.2, and possibly other versions before 2.9.3, allows remote attackers to inject arbitrary web script or HTML via the HTTP X_FORWARDED_FOR header, which is stored by system/libraries/Environment.php but not properly handled by a comments action to main.php.
Advisories
Source ID Title
EUVD EUVD EUVD-2011-0528 Cross-site scripting (XSS) vulnerability in system/modules/comments/Comments.php in Contao CMS 2.9.2, and possibly other versions before 2.9.3, allows remote attackers to inject arbitrary web script or HTML via the HTTP X_FORWARDED_FOR header, which is stored by system/libraries/Environment.php but not properly handled by a comments action to main.php.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-06T21:58:24.570Z

Reserved: 2011-01-20T00:00:00

Link: CVE-2011-0508

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2011-01-20T19:00:10.817

Modified: 2025-04-11T00:51:21.963

Link: CVE-2011-0508

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses