Contao is an open source content management system. Starting in version 4.0.0 and prior to version 4.13.40 and 5.3.4, it is possible to inject insert tags in frontend forms if the output is structured in a very specific way. Contao versions 4.13.40 and 5.3.4 have a patch for this issue. As a workaround, do not output user data from frontend forms next to each other, always separate them by at least one character.
History

Fri, 17 Jan 2025 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Contao
Contao contao
CPEs cpe:2.3:a:contao:contao:*:*:*:*:*:*:*:*
Vendors & Products Contao
Contao contao

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-08-02T00:48:49.484Z

Reserved: 2024-03-06T17:35:00.859Z

Link: CVE-2024-28191

cve-icon Vulnrichment

Updated: 2024-07-29T16:07:42.645Z

cve-icon NVD

Status : Analyzed

Published: 2024-04-09T14:15:08.710

Modified: 2025-01-17T15:39:22.060

Link: CVE-2024-28191

cve-icon Redhat

No data.