SB2019121728 - Input validation error in Contao
Published: December 17, 2019 Updated: April 24, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Input validation error (CVE-ID: CVE-2019-19714)
The vulnerability allows a remote non-authenticated attacker to manipulate data.
Contao 4.8.4 and 4.8.5 has Improper Encoding or Escaping of Output. It is possible to inject insert tags into the login module which will be replaced when the page is rendered.
Remediation
Install update from vendor's website.