Lucene search

K
osvGoogleOSV:CVE-2021-35210
HistoryJun 23, 2021 - 11:15 a.m.

CVE-2021-35210

2021-06-2311:15:08
Google
osv.dev
2

6.9 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

36.1%

Contao 4.5.x through 4.9.x before 4.9.16, and 4.10.x through 4.11.x before 4.11.5, allows XSS. It is possible to inject code into the tl_log table that will be executed in the browser when the system log is called in the back end.

6.9 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

36.1%