CVE-2024-28234 Information
Apr 10, 2024
cve
Description
Contao is an open source content management system. Starting in version 2.0.0 and prior to versions 4.13.40 and 5.3.4 it is possible to inject CSS styles via BBCode in comments. Installations are only affected if BBCode is enabled. Contao versions 4.13.40 and 5.3.4 have a patch for this issue. As a workaround disable BBCode for comments.
Reference
https://github.com/contao/contao/security/advisories/GHSA-j55w-hjpj-825g https://github.com/contao/contao/commit/55b995d8d35da0d36bc6a22c53fe6423ab0c4ae2 https://github.com/contao/contao/commit/6d42e667177c972ae7c219645593c262d7764ce2 https://contao.org/en/security-advisories/insufficient-bbcode-sanitization
Share on: