It is possible to inject code into the tl_log
table that will be executed in the browser when the system log is called in the back end.
Update to Contao 4.9.16 or 4.11.5.
Disable the system log module in the back end for all users (especially admin users).
https://contao.org/en/security-advisories/cross-site-scripting-in-the-system-log-2021
If you have any questions or comments about this advisory, open an issue in contao/contao.
{ "nvd_published_at": "2021-06-23T11:15:00Z", "cwe_ids": [ "CWE-79" ], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2021-06-23T20:24:28Z" }