CVE-2021-35210: XSS
Impact
It is possible to inject code into the tllog table that will be executed in the browser when the system log is called in the back end.
Patches
Update to Contao 4.9.16 or 4.11.5.
Workarounds
Disable the system log module in the back end for all users (especially admin users).
References
https://contao.org/en/security-advisories/cross-site-scripting-in-the-system-log-2021
For more information
If you have any questions or comments about this advisory, open an issue in contao/contao.
Other sources
Contao 4.5.x through 4.9.x before 4.9.16, and 4.10.x through 4.11.x before 4.11.5, allows XSS. It is possible to inject code into the tllog table that will be executed in the browser when the system log is called in the back end.
— MITRE
Cross-site scripting (XSS) vulnerability in the system log
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-35210?
CVE-2021-35210 is a cross-site scripting (XSS) vulnerability in the system log of Contao 4.5.x through 4.9.x before 4.9.16, and 4.10.x through 4.11.x before 4.11.5.
How does CVE-2021-35210 affect the system?
CVE-2021-35210 allows an attacker to inject code into the system log table that will be executed in the browser when the system log is called in the back end.
What is the severity of CVE-2021-35210?
CVE-2021-35210 has a severity rating of 6.1 (medium).
What software versions are affected by CVE-2021-35210?
Contao versions 4.5.x through 4.9.x before 4.9.16, and 4.10.x through 4.11.x before 4.11.5 are affected by CVE-2021-35210.
How can I fix CVE-2021-35210?
To fix CVE-2021-35210, update Contao to version 4.9.16 or 4.11.5 depending on the branch you are using.