{"api_version":"1","generated_at":"2026-07-24T18:35:13+00:00","cve":"CVE-2019-19714","urls":{"html":"https://cve.report/CVE-2019-19714","api":"https://cve.report/api/cve/CVE-2019-19714.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-19714","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-19714"},"summary":{"title":"CVE-2019-19714","description":"Contao 4.8.4 and 4.8.5 has Improper Encoding or Escaping of Output. It is possible to inject insert tags into the login module which will be replaced when the page is rendered.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2019-12-17 15:15:00","updated_at":"2019-12-18 21:25:00"},"problem_types":["CWE-116"],"metrics":[],"references":[{"url":"https://contao.org/en/security-advisories/insert-tag-injection-in-the-login-module.html","name":"https://contao.org/en/security-advisories/insert-tag-injection-in-the-login-module.html","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"Insert tag injection in the login module - Contao","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://contao.org/en/news.html","name":"https://contao.org/en/news.html","refsource":"MISC","tags":["Vendor Advisory"],"title":"Read the official Contao announcements - Contao Open Source CMS (fka TYPOlight)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-19714","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-19714","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"19714","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"contao","cpe5":"contao","cpe6":"4.8.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"19714","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"contao","cpe5":"contao","cpe6":"4.8.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"19714","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"contao","cpe5":"contao","cpe6":"4.8.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"19714","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"contao","cpe5":"contao","cpe6":"4.8.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2019-19714","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Contao 4.8.4 and 4.8.5 has Improper Encoding or Escaping of Output. It is possible to inject insert tags into the login module which will be replaced when the page is rendered."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://contao.org/en/news.html","refsource":"MISC","name":"https://contao.org/en/news.html"},{"refsource":"CONFIRM","name":"https://contao.org/en/security-advisories/insert-tag-injection-in-the-login-module.html","url":"https://contao.org/en/security-advisories/insert-tag-injection-in-the-login-module.html"}]}},"nvd":{"publishedDate":"2019-12-17 15:15:00","lastModifiedDate":"2019-12-18 21:25:00","problem_types":["CWE-116"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"},"exploitabilityScore":3.9,"impactScore":1.4},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:contao:contao:4.8.5:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:contao:contao:4.8.4:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"19714","Ordinal":"162707","Title":"CVE-2019-19714","CVE":"CVE-2019-19714","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"19714","Ordinal":"1","NoteData":"Contao 4.8.4 and 4.8.5 has Improper Encoding or Escaping of Output. It is possible to inject insert tags into the login module which will be replaced when the page is rendered.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"19714","Ordinal":"2","NoteData":"2019-12-17","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"19714","Ordinal":"3","NoteData":"2019-12-17","Type":"Other","Title":"Modified"}]}}}