CVE-2024-28234 Information

Description

Contao is an open source content management system. Starting in version 2.0.0 and prior to versions 4.13.40 and 5.3.4 it is possible to inject CSS styles via BBCode in comments. Installations are only affected if BBCode is enabled. Contao versions 4.13.40 and 5.3.4 have a patch for this issue. As a workaround disable BBCode for comments.

Reference

https://github.com/contao/contao/security/advisories/GHSA-j55w-hjpj-825g https://github.com/contao/contao/commit/55b995d8d35da0d36bc6a22c53fe6423ab0c4ae2 https://github.com/contao/contao/commit/6d42e667177c972ae7c219645593c262d7764ce2 https://contao.org/en/security-advisories/insufficient-bbcode-sanitization

Share on: