Description
Cross-site scripting (XSS) vulnerability in system/modules/comments/Comments.php in Contao CMS 2.9.2, and possibly other versions before 2.9.3, allows remote attackers to inject arbitrary web script or HTML via the HTTP X_FORWARDED_FOR header, which is stored by system/libraries/Environment.php but not properly handled by a comments action to main.php.
Remediation
References
Related Vulnerabilities
WordPress Plugin Custom Dashboard & Login Page-AGCA Cross-Site Request Forgery (6.5.4)
Jenkins URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2026-53436)
WordPress Plugin Slideshow Gallery LITE Multiple Vulnerabilities (1.5.1)
Oracle JRE CVE-2012-1682 Vulnerability (CVE-2012-1682)
Envoy Proxy Uncontrolled Recursion Vulnerability (CVE-2022-23606)