Description
Contao 3.x before 3.5.32 allows XSS via the unsubscribe module in the frontend newsletter extension.
Remediation
References
Related Vulnerabilities
MySQL CVE-2014-4274 Vulnerability (CVE-2014-4274)
WordPress Plugin WP-Lister Lite for Amazon Directory Traversal (0.9.6.35)
Oracle Database Server CVE-2011-0838 Vulnerability (CVE-2011-0838)
Nginx CVE-2023-27729 Vulnerability (CVE-2023-27729)
Plone CMS Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-4191)