CVE-2011-0508Cross-site Scripting in CMS

Severity
4.3MEDIUMNVD
EPSS
0.5%
top 34.04%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 20
Latest updateMay 14

Description

Cross-site scripting (XSS) vulnerability in system/modules/comments/Comments.php in Contao CMS 2.9.2, and possibly other versions before 2.9.3, allows remote attackers to inject arbitrary web script or HTML via the HTTP X_FORWARDED_FOR header, which is stored by system/libraries/Environment.php but not properly handled by a comments action to main.php.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-gfg7-fg26-2g7j: Cross-site scripting (XSS) vulnerability in system/modules/comments/Comments2022-05-14
CVEList
CVE-2011-0508: Cross-site scripting (XSS) vulnerability in system/modules/comments/Comments2011-01-20
CVE-2011-0508 — Cross-site Scripting in Contao CMS | cvebase