Contao has insufficient BBCode sanitizer
Vulnerability Description
Contao is an open source content management system. Starting in version 2.0.0 and prior to versions 4.13.40 and 5.3.4, it is possible to inject CSS styles via BBCode in comments. Installations are only affected if BBCode is enabled. Contao versions 4.13.40 and 5.3.4 have a patch for this issue. As a workaround, disable BBCode for comments.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-28234
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/contao/contao/security/advisories/GHSA-j55w-hjpj-825g
- https://github.com/contao/contao/commit/55b995d8d35da0d36bc6a22c53fe6423ab0c4ae2
- https://github.com/contao/contao/commit/6d42e667177c972ae7c219645593c262d7764ce2
- https://contao.org/en/security-advisories/insufficient-bbcode-sanitization
More from contao
View All →Affected Vendor
contao
View all reports →