From 94aab7bec4b0f6b8764ea20b9bef16319d99e03e Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 17 Apr 2025 12:48:20 +0000 Subject: [PATCH] Publish Advisories GHSA-h58v-c6rf-g9f7 GHSA-hr3h-x6gq-rqcp GHSA-m8x6-6r63-qvj2 --- .../2021/07/GHSA-h58v-c6rf-g9f7/GHSA-h58v-c6rf-g9f7.json | 4 ++-- .../2021/08/GHSA-hr3h-x6gq-rqcp/GHSA-hr3h-x6gq-rqcp.json | 2 +- .../2022/05/GHSA-m8x6-6r63-qvj2/GHSA-m8x6-6r63-qvj2.json | 2 +- 3 files changed, 4 insertions(+), 4 deletions(-) diff --git a/advisories/github-reviewed/2021/07/GHSA-h58v-c6rf-g9f7/GHSA-h58v-c6rf-g9f7.json b/advisories/github-reviewed/2021/07/GHSA-h58v-c6rf-g9f7/GHSA-h58v-c6rf-g9f7.json index 481334b3e91..ecd4083d82c 100644 --- a/advisories/github-reviewed/2021/07/GHSA-h58v-c6rf-g9f7/GHSA-h58v-c6rf-g9f7.json +++ b/advisories/github-reviewed/2021/07/GHSA-h58v-c6rf-g9f7/GHSA-h58v-c6rf-g9f7.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-h58v-c6rf-g9f7", - "modified": "2024-04-22T18:36:58Z", + "modified": "2025-04-17T12:45:28Z", "published": "2021-07-01T17:00:04Z", "aliases": [ "CVE-2021-35210" ], "summary": "Cross site scripting in the system log", - "details": "### Impact\n\nIt is possible to inject code into the `tl_log` table that will be executed in the browser when the system log is called in the back end.\n\n### Patches\n\nUpdate to Contao 4.9.16 or 4.11.5.\n\n### Workarounds\n\nDisable the system log module in the back end for all users (especially admin users).\n\n### References\n\nhttps://contao.org/en/security-advisories/cross-site-scripting-in-the-system-log-2021\n\n### For more information\n\nIf you have any questions or comments about this advisory, open an issue in [contao/contao](https://github.com/contao/contao/issues/new/choose).\n", + "details": "### Impact\n\nIt is possible to inject code into the `tl_log` table that will be executed in the browser when the system log is called in the back end.\n\n### Patches\n\nUpdate to Contao 4.9.16 or 4.11.5.\n\n### Workarounds\n\nDisable the system log module in the back end for all users (especially admin users).\n\n### References\n\nhttps://contao.org/en/security-advisories/cross-site-scripting-in-the-system-log-2021\n\n### For more information\n\nIf you have any questions or comments about this advisory, open an issue in [contao/contao](https://github.com/contao/contao/issues/new/choose).", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/github-reviewed/2021/08/GHSA-hr3h-x6gq-rqcp/GHSA-hr3h-x6gq-rqcp.json b/advisories/github-reviewed/2021/08/GHSA-hr3h-x6gq-rqcp/GHSA-hr3h-x6gq-rqcp.json index 4626c43b905..3999392508c 100644 --- a/advisories/github-reviewed/2021/08/GHSA-hr3h-x6gq-rqcp/GHSA-hr3h-x6gq-rqcp.json +++ b/advisories/github-reviewed/2021/08/GHSA-hr3h-x6gq-rqcp/GHSA-hr3h-x6gq-rqcp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hr3h-x6gq-rqcp", - "modified": "2024-04-22T18:41:57Z", + "modified": "2025-04-17T12:45:11Z", "published": "2021-08-25T14:45:01Z", "aliases": [ "CVE-2021-35955" diff --git a/advisories/github-reviewed/2022/05/GHSA-m8x6-6r63-qvj2/GHSA-m8x6-6r63-qvj2.json b/advisories/github-reviewed/2022/05/GHSA-m8x6-6r63-qvj2/GHSA-m8x6-6r63-qvj2.json index 11fc76b9eb9..2646d1bcae7 100644 --- a/advisories/github-reviewed/2022/05/GHSA-m8x6-6r63-qvj2/GHSA-m8x6-6r63-qvj2.json +++ b/advisories/github-reviewed/2022/05/GHSA-m8x6-6r63-qvj2/GHSA-m8x6-6r63-qvj2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m8x6-6r63-qvj2", - "modified": "2024-04-22T18:40:57Z", + "modified": "2025-04-17T12:44:51Z", "published": "2022-05-20T19:54:56Z", "aliases": [ "CVE-2022-24899"