CVE-2023-36806

MEDIUM EPSS 41.0%
Published Jul 25, 20232y ago · Modified Jun 17, 20262w ago
5.4 CVSS 3.1
Medium
Find Similar
Published Jul 25, 2023 2y ago
Last Modified Jun 17, 2026 2w ago

Description

Contao is an open source content management system. Starting in version 4.0.0 and prior to versions 4.9.42, 4.13.28, and 5.1.10, it is possible for untrusted backend users to inject malicious code into headline fields in the back end, which will be executed both in the element preview (back end) and on the website (front end). Installations are only affected if there are untrusted back end users who have the rights to modify headline fields, or other fields using the input unit widget. Contao 4.9.42, 4.13.28, and 5.1.10 have a patch for this issue. As a workaround, disable the login for all untrusted back end users.

CVSS Details

Base Score
5.4
Exploitability
2.3
Impact
2.7
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Attack Vector Network
Attack Complexity Low
Privileges Required Low
User Interaction Required
Scope Changed
Confidentiality Low
Integrity Low
Availability None

Threat Intelligence

EPSS Exploit Probability
41.0% percentile
Exploit & Patch Status
Public Exploit Known
Patch Available

Weaknesses 1

CWE-79 Cross-site Scripting Injection

Affected Products 3

VendorProductVersionRange
contaocontao*≥4.0.0  –  <4.9.42
contaocontao*≥4.10.0  –  <4.13.28
contaocontao*≥5.0.0  –  <5.1.10

References 5

  • github.com https://github.com/contao/contao/commit/5c9aff32cfc1f7dc452a045862ac2f86a6b9b4b4
    Patch
  • github.com https://github.com/contao/contao/commit/c98585d36baa25fda69c062421e7e7eadc53c82b
    Patch
  • github.com https://github.com/contao/contao/commit/ccb64c777eb0f9c0e6490c9135d80e915d37cd32
    Patch
  • github.com https://github.com/contao/contao/security/advisories/GHSA-4gpr-p634-922x
    Vendor Advisory
  • herolab.usd.de https://herolab.usd.de/security-advisories/usd-2023-0020/
    ExploitThird Party Advisory

Remediation

  • github.com https://github.com/contao/contao/commit/5c9aff32cfc1f7dc452a045862ac2f86a6b9b4b4
    Patch
  • github.com https://github.com/contao/contao/commit/c98585d36baa25fda69c062421e7e7eadc53c82b
    Patch
  • github.com https://github.com/contao/contao/commit/ccb64c777eb0f9c0e6490c9135d80e915d37cd32
    Patch