MEDIUM6.1
GHSA-h58v-c6rf-g9f7
Cross site scripting in the system log
Quick fix
GHSA-h58v-c6rf-g9f7 — contao/core-bundle: upgrade to the fixed version with the command below.
composer require contao/core-bundle:^4.9.16Details
### Impact
It is possible to inject code into the `tl_log` table that will be executed in the browser when the system log is called in the back end.
### Patches
Update to Contao 4.9.16 or 4.11.5.
### Workarounds
Disable the system log module in the back end for all users (especially admin users).
### References
https://contao.org/en/security-advisories/cross-site-scripting-in-the-system-log-2021
### For more information
If you have any questions or comments about this advisory, open an issue in [contao/contao](https://github.com/contao/contao/issues/new/choose).
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/contao/core-bundle
Introduced in:
4.5.0Fixed in: 4.9.16Fix
composer require contao/core-bundle:^4.9.16Packagist/contao/core-bundle
Introduced in:
4.10.0Fixed in: 4.11.5Fix
composer require contao/core-bundle:^4.11.5Packagist/contao/contao
Introduced in:
4.5.0Fixed in: 4.9.16Fix
composer require contao/contao:^4.9.16Packagist/contao/contao
Introduced in:
4.10.0Fixed in: 4.11.5Fix
composer require contao/contao:^4.11.5References
- https://github.com/contao/contao/security/advisories/GHSA-h58v-c6rf-g9f7[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2021-35210[ADVISORY]
- https://contao.org/en/security-advisories/cross-site-scripting-in-the-system-log-2021.html[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/contao/contao/CVE-2021-35210.yaml[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/contao/core-bundle/CVE-2021-35210.yaml[WEB]
- https://github.com/contao/contao[PACKAGE]