Cross-Site Scripting Vulnerability in Contao Web Application
CVE-2021-35955
4.8MEDIUM
What is CVE-2021-35955?
The vulnerability in Contao versions 4.0.0 and above allows attackers to exploit backend Cross-Site Scripting (XSS) via HTML attributes in an HTML field. This can potentially lead to unauthorized access and manipulation within the application's backend interface. Users are advised to upgrade to versions 4.4.56, 4.9.18, or 4.11.7 to mitigate this risk.
