Impact
The vulnerability is a classic unsanitized output issue that allows any unauthenticated visitor to submit a comment whose email or website fields are rendered directly without proper encoding. When a backend user opens the Comments module, attacker-controlled JavaScript executes in the Contao backend origin with that user’s session privileges. This is a stored XSS that can lead to session hijacking or code execution on the backend, classed under CWE-79 and CWE-116. The impact is malicious script execution in the CMS backend, potentially compromising the accounts of moderator users.
Affected Systems
Affected from Contao CMS version 4.0.0 up to and including the 5.3.49 release and 5.7.11. The fix is delivered in releases 5.3.50 and 5.7.12, so any version newer than 5.3.50 or 5.7.12 is considered safe. The downstream product remains the Contao CMS platform for all affected instances.
Risk and Exploitability
With a CVSS score of 9.3 the vulnerability is rated critical. The EPSS score is not available, but the lack of a KEV listing does not diminish that the issue is widely usable. An attacker only needs to craft a malicious comment on a publicly exposed comment form; no authentication or privileged access is required. If a moderator or other backend user subsequently opens the Comments module, the stored script runs within that session, giving the attacker the same privileges as the moderator. Because unpublished comments are still visible to moderators, the usual moderation workflow does not mitigate the risk.
OpenCVE Enrichment