Users can insert malicious code into file names when uploading files, which is then executed in tooltips and popups in the backend.
Update to Contao 4.13.40 or Contao 5.3.4.
Disable uploads for untrusted users.
https://contao.org/en/security-advisories/cross-site-scripting-in-the-file-manager
If you have any questions or comments about this advisory, open an issue in contao/contao.
Thanks to Alexander Wuttke for reporting this vulnerability.
{ "nvd_published_at": "2024-04-09T14:15:08Z", "cwe_ids": [ "CWE-79" ], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2024-04-09T18:52:46Z" }