GHSA-4gpr-p634-922x
Cross site scripting via input unit widget
Quick fix
GHSA-4gpr-p634-922x — contao/core-bundle: upgrade to the fixed version with the command below.
composer require contao/core-bundle:^4.9.42Details
### Impact
Authenticated users can inject malicious code in widgets with units, which is then executed both in the element preview (back end) and on the website (front end).
### Patches
Update to Contao 4.9.42, 4.13.28 or 5.1.10.
### Workarounds
Disable login for all untrusted back end users.
### References
https://contao.org/en/security-advisories/cross-site-scripting-in-widgets-with-units
### For more information
If you have any questions or comments about this advisory, open an issue in [contao/contao](https://github.com/contao/contao/issues/new/choose).
### Credits
Thanks to Christian Pöschl and Fabian Brenner from usd AG for reporting this vulnerability.
Are you affected?
Enter the version of the package you're using.
Affected packages
4.0.0Fixed in: 4.9.42composer require contao/core-bundle:^4.9.424.10.0Fixed in: 4.13.28composer require contao/core-bundle:^4.13.285.0.0Fixed in: 5.1.10composer require contao/core-bundle:^5.1.10References
- https://github.com/contao/contao/security/advisories/GHSA-4gpr-p634-922x[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2023-36806[ADVISORY]
- https://github.com/contao/contao/commit/5c9aff32cfc1f7dc452a045862ac2f86a6b9b4b4[WEB]
- https://github.com/contao/contao/commit/c98585d36baa25fda69c062421e7e7eadc53c82b[WEB]
- https://github.com/contao/contao/commit/ccb64c777eb0f9c0e6490c9135d80e915d37cd32[WEB]
- https://github.com/contao/contao[PACKAGE]
- https://herolab.usd.de/security-advisories/usd-2023-0020[WEB]