VDB
Sign up
MEDIUM6.6

GHSA-4gpr-p634-922x

Cross site scripting via input unit widget

Quick fix

GHSA-4gpr-p634-922x — contao/core-bundle: upgrade to the fixed version with the command below.

composer require contao/core-bundle:^4.9.42

Details

### Impact

Authenticated users can inject malicious code in widgets with units, which is then executed both in the element preview (back end) and on the website (front end).

### Patches

Update to Contao 4.9.42, 4.13.28 or 5.1.10.

### Workarounds

Disable login for all untrusted back end users.

### References

https://contao.org/en/security-advisories/cross-site-scripting-in-widgets-with-units

### For more information

If you have any questions or comments about this advisory, open an issue in [contao/contao](https://github.com/contao/contao/issues/new/choose).

### Credits

Thanks to Christian Pöschl and Fabian Brenner from usd AG for reporting this vulnerability.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/contao/core-bundle
Introduced in: 4.0.0Fixed in: 4.9.42
Fixcomposer require contao/core-bundle:^4.9.42
Packagist/contao/core-bundle
Introduced in: 4.10.0Fixed in: 4.13.28
Fixcomposer require contao/core-bundle:^4.13.28
Packagist/contao/core-bundle
Introduced in: 5.0.0Fixed in: 5.1.10
Fixcomposer require contao/core-bundle:^5.1.10

References