VYPR
Medium severity6.1NVD Advisory· Published Mar 16, 2020· Updated Jun 17, 2026

CVE-2018-10125

CVE-2018-10125

Description

Contao before 4.5.7 has XSS in the system log.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
contao/contaoPackagist
>= 4.0.0, < 4.4.184.4.18
contao/contaoPackagist
>= 4.5.0, < 4.5.84.5.8
contao/core-bundlePackagist
>= 4.0.0, < 4.4.184.4.18
contao/core-bundlePackagist
>= 4.5.0, < 4.5.84.5.8
contao/corePackagist
>= 3.0.0, < 3.5.353.5.35
contao/core-bundlePackagist
>= 3.0.0, < 3.5.353.5.35

Affected products

9
  • Contao/CMS5 versions
    cpe:2.3:a:contao:contao:*:*:*:*:*:*:*:*+ 4 more
    • cpe:2.3:a:contao:contao:*:*:*:*:*:*:*:*range: >=3.0.0,<=3.5.33
    • cpe:2.3:a:contao:contao:4.0.0:-:*:*:*:*:*:*
    • cpe:2.3:a:contao:contao:4.1.0:-:*:*:*:*:*:*
    • cpe:2.3:a:contao:contao:4.2.0:-:*:*:*:*:*:*
    • cpe:2.3:a:contao:contao:4.3.0:-:*:*:*:*:*:*
  • Contao/Contaodescription
  • ghsa-coords3 versions
    >= 4.0.0, < 4.4.18+ 2 more
    • (no CPE)range: >= 4.0.0, < 4.4.18
    • (no CPE)range: >= 3.0.0, < 3.5.35
    • (no CPE)range: >= 4.0.0, < 4.4.18

Patches

Vulnerability mechanics

References

8

News mentions

0

No linked articles in our index yet.