Lucene search

K
contaoContao orgCONTAO:CROSS-SITE-SCRIPTING-IN-WIDGETS-WITH-UNITS
HistoryJul 25, 2023 - 12:00 a.m.

Cross site scripting in widgets with units

2023-07-2500:00:00
Contao org
contao.org
13
cross site scripting
widgets
units
contao
code injection
authentication
vulnerability
versions
upgrade
github advisory

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L

0.001 Low

EPSS

Percentile

26.5%

Date: 2023-07-25 CVE ID: CVE-2023-36806

Authenticated users can inject malicious code in widgets with units, which is then executed both in the element preview (back end) and on the website (front end).

Thanks to Christian Pöschl and Fabian Brenner from usd AG for reporting this vulnerability.

Affected versions

Contao 4.0
Contao 4.1
Contao 4.2
Contao 4.3
Contao 4.4
Contao 4.5
Contao 4.6
Contao 4.7
Contao 4.8
Contao 4.9 up to 4.9.41
Contao 4.10
Contao 4.11
Contao 4.12
Contao 4.13 up to 4.13.27
Contao 5.0
Contao 5.1 up to 5.1.9

Suggested solution

Upgrade to Contao 4.9.42, 4.13.28 or 5.1.10.

More information

<https://github.com/contao/contao/security/advisories/GHSA-4gpr-p634-922x&gt;

Rows per page:
1-10 of 161

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L

0.001 Low

EPSS

Percentile

26.5%

Related for CONTAO:CROSS-SITE-SCRIPTING-IN-WIDGETS-WITH-UNITS