Contao Cross-site Scripting vulnerabililty
Moderate severity
GitHub Reviewed
Published
Sep 21, 2023
to the GitHub Advisory Database
•
Updated May 15, 2024
Description
Published by the National Vulnerability Database
Sep 21, 2023
Published to the GitHub Advisory Database
Sep 21, 2023
Last updated
May 15, 2024
Reviewed
May 15, 2024
Contao 3.x before 3.5.32 allows Cross-site Scripting (XSS) via the unsubscribe module in the frontend newsletter extension.
References