CVE-2021-35210
Dashboard / Vulnerabilities / CVE-2021-35210
Summary:
Details: Contao 4.5.x through 4.9.x before 4.9.16, and 4.10.x through 4.11.x before 4.11.5, allows XSS. It is possible to inject code into the tl_log table that will be executed in the browser when the system log is called in the back end.
References: https://contao.org/en/security-advisories/cross-site-scripting-in-the-system-log-2021.html, https://github.com/contao/contao/security/advisories/GHSA-h58v-c6rf-g9f7
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
Introduced- b09b4d51d13d37b4bfcd2ef4314fc6a20184dc55
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
