CVE-2019-19714
Summary
| CVE | CVE-2019-19714 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-12-17 15:15:00 UTC |
| Updated | 2019-12-18 21:25:00 UTC |
| Description | Contao 4.8.4 and 4.8.5 has Improper Encoding or Escaping of Output. It is possible to inject insert tags into the login module which will be replaced when the page is rendered. |
Risk And Classification
Problem Types: CWE-116
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Insert tag injection in the login module - Contao | CONFIRM | contao.org | Vendor Advisory |
| Read the official Contao announcements - Contao Open Source CMS (fka TYPOlight) | MISC | contao.org | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.