Contao 4.8.4 and 4.8.5 has Improper Encoding or Escaping of Output. It is possible to inject insert tags into the login module which will be replaced when the page is rendered.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-0796 | Contao 4.8.4 and 4.8.5 has Improper Encoding or Escaping of Output. It is possible to inject insert tags into the login module which will be replaced when the page is rendered. |
Github GHSA |
GHSA-jc43-qrrp-98f5 | Insert tag injection in the Contao login module |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T02:25:12.463Z
Reserved: 2019-12-11T00:00:00
Link: CVE-2019-19714
No data.
Status : Modified
Published: 2019-12-17T15:15:25.613
Modified: 2024-11-21T04:35:14.733
Link: CVE-2019-19714
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA