MEDIUM6.1
GHSA-pj4j-287j-f742
Cross-site Scripting in Contao
Quick fix
GHSA-pj4j-287j-f742 — contao/contao: upgrade to the fixed version with the command below.
composer require contao/contao:^4.4.18Details
Contao before 4.5.7 has XSS in the system log.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/contao/contao
Introduced in:
4.0.0Fixed in: 4.4.18Fix
composer require contao/contao:^4.4.18Packagist/contao/core-bundle
Introduced in:
4.0.0Fixed in: 4.4.18Fix
composer require contao/core-bundle:^4.4.18Packagist/contao/core-bundle
Introduced in:
4.5.0Fixed in: 4.5.8Fix
composer require contao/core-bundle:^4.5.8Packagist/contao/core-bundle
Introduced in:
3.0.0Fixed in: 3.5.35Fix
composer require contao/core-bundle:^3.5.35References
- https://nvd.nist.gov/vuln/detail/CVE-2018-10125[ADVISORY]
- https://contao.org/en/news/contao-3_5_35.html[WEB]
- https://contao.org/en/news/contao-4_4_18.html[WEB]
- https://contao.org/en/security-advisories/cross-site-scripting-in-the-system-log.html[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/contao/contao/CVE-2018-10125.yaml[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/contao/core-bundle/CVE-2018-10125.yaml[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/contao/core/CVE-2018-10125.yaml[WEB]