Contao before 4.4.52, 4.9.x before 4.9.6, and 4.10.x before 4.10.1 have Improper Input Validation. It is possible to inject insert tags in front end forms which will be replaced when the page is rendered.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-1014 | Contao before 4.4.52, 4.9.x before 4.9.6, and 4.10.x before 4.10.1 have Improper Input Validation. It is possible to inject insert tags in front end forms which will be replaced when the page is rendered. |
Github GHSA |
GHSA-f7wm-x4gw-6m23 | Contao Insert tag injection in forms |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T15:40:36.950Z
Reserved: 2020-09-18T00:00:00
Link: CVE-2020-25768
No data.
Status : Modified
Published: 2020-10-07T21:15:14.963
Modified: 2024-11-21T05:18:43.020
Link: CVE-2020-25768
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA