Description Contao before 4.5.7 has XSS in the system log. Remediation References CVE-2018-10125 Related Vulnerabilities IBMHttpServer Other Vulnerability (CVE-2004-0492) WordPress Plugin Catch Themes Demo Import Security Bypass (1.5) Rukovoditel Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2020-11822) WordPress Plugin AdVert Cross-Site Scripting (1.0.5) WordPress Plugin Event List SQL Injection (0.7.8) Severity Medium Classification CVE-2018-10125 CWE-707 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Tags Missing Update Known Vulnerabilities