Contao Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2018-5478
Contao 3.x before 3.5.32 allows XSS via the unsubscribe module in the frontend newsletter extension.
Contao 3.x before 3.5.32 allows XSS via the unsubscribe module in the frontend newsletter extension.