CVE-2019-19714: Medium severity contao cms vulnerability
Impact
It is possible to inject insert tags into the login module which will be replaced when the page is rendered.
Patches
Update to Contao 4.8.6.
Workarounds
None.
References
https://contao.org/en/security-advisories/insert-tag-injection-in-the-login-module
For more information
If you have any questions or comments about this advisory, open an issue in contao/contao.
Other sources
Contao 4.8.4 and 4.8.5 has Improper Encoding or Escaping of Output. It is possible to inject insert tags into the login module which will be replaced when the page is rendered.
— MITRE
Insert tag injection in the login module
Affected Software
Event History
Frequently Asked Questions
What is the impact of CVE-2019-19714?
It is possible to inject insert tags into the login module which will be replaced when the page is rendered.
How can I patch CVE-2019-19714?
Update to Contao 4.8.6.
Are there any workarounds for CVE-2019-19714?
No, there are no workarounds.
Where can I find more information about CVE-2019-19714?
You can find more information about CVE-2019-19714 at the following references: [Link](https://contao.org/en/security-advisories/insert-tag-injection-in-the-login-module.html), [Link](https://github.com/contao/contao/security/advisories/GHSA-jc43-qrrp-98f5), [Link](https://nvd.nist.gov/vuln/detail/CVE-2019-19714)
What is the severity of CVE-2019-19714?
CVE-2019-19714 has a severity rating of medium.