Security Advisory
CVE-2019-19714
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
Contao 4.8.4 and 4.8.5 has Improper Encoding or Escaping of Output. It is possible to inject insert tags into the login module which will be replaced when the page is rendered.