CVE-2020-25768
Summary
| CVE | CVE-2020-25768 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-10-07 21:15:00 UTC |
| Updated | 2021-07-21 11:39:00 UTC |
| Description | Contao before 4.4.52, 4.9.x before 4.9.6, and 4.10.x before 4.10.1 have Improper Input Validation. It is possible to inject insert tags in front end forms which will be replaced when the page is rendered. |
Risk And Classification
Problem Types: CWE-20 | CWE-74
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Announcements | MISC | community.contao.org | Release Notes, Vendor Advisory |
| Insert tag injection in forms - Contao | CONFIRM | contao.org | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.