GHSA-hr3h-x6gq-rqcp

    Dashboard / Vulnerabilities / GHSA-hr3h-x6gq-rqcp

    GHSA-hr3h-x6gq-rqcp

    Published: 25 Aug 2021Last Modified: 8 Jul 2026

    Summary: Cross site scripting via HTML attributes in the back end

    Details: ### Impact It is possible for untrusted users to inject malicious code into HTML attributes in the back end, which will be executed both in the element preview (back end) and on the website (front end). Installations are only affected if there are untrusted back end users who have the rights to modify HTML fields (e.g. TinyMCE). ### Patches Update to Contao 4.4.56, 4.9.18 or 4.11.7 ### Workarounds Disable all fields that allow HTML for untrusted back end users or disable the login for these users. ### References https://contao.org/en/security-advisories/cross-site-scripting-via-html-attributes-in-the-back-end ### For more information If you have any questions or comments about this advisory, open an issue in [contao/contao](https://github.com/contao/contao/issues/new/choose). ### Credits Thanks to Mikhail Khramenkov and Moritz Vondano for reporting this security issue.

    Affected packages

    Package

    Name: contao/core-bundle

    Purl: pkg:composer/contao/core-bundle

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 4.0.0
    Fixed -4.4.56

    Affected versions

    4.0.0
    4.0.1
    4.0.2
    4.0.3
    4.0.4

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-hr3h-x6gq-rqcp | CVE-DB