Contao is an open source content management system. Starting in version 4.0.0 and prior to version 4.13.40 and 5.3.4, it is possible to inject insert tags in frontend forms if the output is structured in a very specific way. Contao versions 4.13.40 and 5.3.4 have a patch for this issue. As a workaround, do not output user data from frontend forms next to each other, always separate them by at least one character.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-04-09T13:54:22.129Z

Updated: 2024-08-02T00:48:49.484Z

Reserved: 2024-03-06T17:35:00.859Z

Link: CVE-2024-28191

cve-icon Vulnrichment

Updated: 2024-07-29T16:07:42.645Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-04-09T14:15:08.710

Modified: 2024-04-10T13:24:22.187

Link: CVE-2024-28191

cve-icon Redhat

No data.