Description
Contao 4.8.4 and 4.8.5 has Improper Encoding or Escaping of Output. It is possible to inject insert tags into the login module which will be replaced when the page is rendered.
Remediation
References
Related Vulnerabilities
MySQL Improper Access Control Vulnerability (CVE-2015-3152)
Drupal Core 8.x.x Remote Code Execution (8.0.0 - 8.4.8)
Python Use After Free Vulnerability (CVE-2018-1000030)
Apache HTTP Server Permissions, Privileges, and Access Controls Vulnerability (CVE-2015-3185)
WebLogic URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2026-35258)