CVE-2019-19714
—CVSS 3.1
5.3 medium
EPSS
<1%p55
Published
()
Modified
Description
Contao 4.8.4 and 4.8.5 has Improper Encoding or Escaping of Output. It is possible to inject insert tags into the login module which will be replaced when the page is rendered.
- Vendors
- contao
- Products
- contao
- Weakness
- CWE-116
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.