CVE-2024-28234

medium

Description

Contao is an open source content management system. Starting in version 2.0.0 and prior to versions 4.13.40 and 5.3.4, it is possible to inject CSS styles via BBCode in comments. Installations are only affected if BBCode is enabled. Contao versions 4.13.40 and 5.3.4 have a patch for this issue. As a workaround, disable BBCode for comments.

References

https://github.com/contao/contao/security/advisories/GHSA-j55w-hjpj-825g

https://github.com/contao/contao/commit/6d42e667177c972ae7c219645593c262d7764ce2

https://github.com/contao/contao/commit/55b995d8d35da0d36bc6a22c53fe6423ab0c4ae2

https://contao.org/en/security-advisories/insufficient-bbcode-sanitization

Details

Source: Mitre, NVD

Published: 2024-04-09

Updated: 2025-01-02

Risk Information

CVSS v2

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 4.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N

Severity: Medium

EPSS

EPSS: 0.00531