CVE-2024-28234

CVSS 3.1 Score 4.7 of 10 (medium)

Details

Published Apr 9, 2024
Updated: Jan 2, 2025
CWE ID 74

Summary

CVE-2024-28234 is a vulnerability affecting the open-source content management system Contao. Versions prior to 4.13.40 and 5.3.4, starting from 2.0.0, are at risk. This issue allows attackers to inject CSS styles via BBCode in comments. The vulnerability only impacts installations with BBCode enabled. Contao has released patches for versions 4.13.40 and 5.3.4 to mitigate this issue. As a temporary solution, administrators can disable BBCode for comments.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share