Vulnerability GHSA-j55w-hjpj-825g

Medium Risk
MEDIUM RISK
CVSS Score: 4.3
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
2 years ago
April 09, 2024 at 06:52 PM UTC
Contao: Insufficient BBCode sanitizer
4.0.0 - 4.0.3 and 4.1.0 - 4.1.2 and 4.2.0 - 4.2.1 and 4.3.0 - 4.3.11 and 4.4.0 - 4.4.57 and 4.5.0 - 4.5.14 and 4.6.0 - 4.6.14 and 4.7.0 - 4.7.7 and 4.8.0 - 4.8.8 and 4.9.0 - 4.9.42 and 4.10.0 - 4.10.7 and 4.11.0 - 4.11.9 and 4.12.0 - 4.12.7 and 4.13.0 - 4.13.39 and 5.0.0 - 5.0.10 and 5.1.0 - 5.1.11 and 5.2.0 - 5.2.10 and 5.3.0 - 5.3.3
4.0.0 - 4.0.3 and 4.1.0 - 4.1.2 and 4.2.0 - 4.2.1 and 4.3.0 - 4.3.11 and 4.4.0 - 4.4.57 and 4.5.0 - 4.5.14 and 4.6.0 - 4.6.14 and 4.7.0 - 4.7.7 and 4.8.0 - 4.8.8 and 4.9.0 - 4.9.42 and 4.10.0 - 4.10.7 and 4.11.0 - 4.11.9 and 4.12.0 - 4.12.7 and 4.13.0 - 4.13.39 and 5.0.0 - 5.0.10 and 5.1.0 - 5.1.11 and 5.2.0 - 5.2.10 and 5.3.0 - 5.3.3

Summary

Contao: Insufficient BBCode sanitizer

Details

Impact

If BBCode is enabled for comments, users can inject CSS styles.

Patches

Update to Contao 4.13.40 or 5.3.4.

Workarounds

Disable BBCode for comments.

References

https://contao.org/en/security-advisories/insufficient-bbcode-sanitization

For more information

If you have any questions or comments about this advisory, open an issue in contao/contao.

Impacted packages

Timeline

Published
2 years ago
April 09, 2024 at 06:52 PM UTC
Fixed (4.13.40)
2 years ago
April 09, 2024 at 05:18 AM UTC
Fixed (5.3.4)
2 years ago
April 09, 2024 at 05:18 AM UTC
Last Modified
29 days ago
September 10, 2026 at 03:50 AM UTC