Cross-Site Scripting Vulnerability in Contao by Contao GmbH & Co. KG
CVE-2021-35210

6.1MEDIUM

Key Information:

Vendor

Contao

Status
Vendor
CVE Published:
23 June 2021

What is CVE-2021-35210?

A vulnerability exists in Contao versions 4.5.x through 4.9.x prior to 4.9.16, and versions 4.10.x through 4.11.x before 4.11.5 that allows attackers to inject malicious scripts into the system's log data. This code can be executed in the user's browser when accessing the system log in the backend, potentially compromising the security of the application and exposing sensitive information.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.