ZeroHour

CVE-2019-19714

CVSS 3.1
5.3 medium
EPSS
<1%p55
Published
()
Modified
Description

Contao 4.8.4 and 4.8.5 has Improper Encoding or Escaping of Output. It is possible to inject insert tags into the login module which will be replaced when the page is rendered.

Vendors
contao
Products
contao
Weakness
CWE-116
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.