CVE-2021-35210
23.06.2021, 11:15
Contao 4.5.x through 4.9.x before 4.9.16, and 4.10.x through 4.11.x before 4.11.5, allows XSS. It is possible to inject code into the tl_log table that will be executed in the browser when the system log is called in the back end.
Vendor | Product | Version |
---|---|---|
contao | contao | 4.5.0 ≤ 𝑥 < 4.9.16 |
contao | contao | 4.10.0 ≤ 𝑥 < 4.11.5 |
𝑥
= Vulnerable software versions
References