VDB
Sign up
MEDIUM6.1

GHSA-mpg7-2rx9-h5qp

Contao Cross-site Scripting vulnerabililty

Quick fix

GHSA-mpg7-2rx9-h5qp — contao/core: upgrade to the fixed version with the command below.

composer require contao/core:^3.5.32

Details

Contao 3.x before 3.5.32 allows Cross-site Scripting (XSS) via the unsubscribe module in the frontend newsletter extension.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/contao/core
Introduced in: 3.0.0Fixed in: 3.5.32
Fixcomposer require contao/core:^3.5.32

References