Contao Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2021-35955 - Vulnerability Database

Contao Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2021-35955

Medium
Reference: CVE-2021-35955
Title: Contao Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:

Contao gt4.0.0 allows backend XSS via HTML attributes to an HTML field. Fixed in 4.4.56 4.9.18 4.11.7.