Description
Contao 3.x before 3.5.32 allows XSS via the unsubscribe module in the frontend newsletter extension.
Remediation
References
Related Vulnerabilities
ATutor Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2015-1583)
RubyGems Loop with Unreachable Exit Condition ('Infinite Loop') Vulnerability (CVE-2018-1000075)
GlassFish CVE-2016-5528 Vulnerability (CVE-2016-5528)
PHP Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-3065)