Contao Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2021-35210 - Vulnerability Database

Contao Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2021-35210

Medium
Reference: CVE-2021-35210
Title: Contao Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:

Contao 4.5.x through 4.9.x before 4.9.16 and 4.10.x through 4.11.x before 4.11.5 allows XSS. It is possible to inject code into the tl_log table that will be executed in the browser when the system log is called in the back end.