Skip to content

Insert tag injection in the Contao login module

Moderate severity GitHub Reviewed Published Dec 17, 2019 in contao/contao • Updated Apr 22, 2024

Package

composer contao/contao (Composer)

Affected versions

>= 4.8.4, < 4.8.6

Patched versions

4.8.6
composer contao/core-bundle (Composer)
>= 4.8.4, < 4.8.6
4.8.6

Description

@leofeyer leofeyer published to contao/contao Dec 17, 2019
Reviewed Dec 17, 2019
Published to the GitHub Advisory Database Dec 17, 2019
Last updated Apr 22, 2024

Severity

Moderate
5.3
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
None
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Weaknesses

CVE ID

CVE-2019-19714

GHSA ID

GHSA-jc43-qrrp-98f5

Source code

Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.