<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Comments-Bundle (5.4.0-RC1 &lt;= v &lt; 5.7.12) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/comments-bundle-5.4.0-rc1--v--5.7.12/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 09 Oct 2026 21:23:18 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/comments-bundle-5.4.0-rc1--v--5.7.12/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stored Cross-Site Scripting in Contao Comments Bundle</title><link>https://feed.craftedsignal.io/briefs/2026-10-contao-xss/</link><pubDate>Fri, 09 Oct 2026 21:23:18 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-contao-xss/</guid><description>An unauthenticated stored XSS vulnerability in the Contao comments-bundle allows remote attackers to execute arbitrary JavaScript in the context of administrative sessions, potentially leading to full system compromise.</description><content:encoded><![CDATA[<p>The Contao comments-bundle is vulnerable to stored cross-site scripting (XSS) due to improper input sanitization in the front-end comment submission mechanism. Tracked as CVE-2026-107845, this vulnerability allows unauthenticated attackers to submit comments containing malicious payloads that persist within the application database. When an administrator or moderator accesses the back-end Comments module to review pending submissions, the injected script executes automatically within their browser session.</p>
<p>Because the Contao back-end lacks a robust Content-Security-Policy (CSP), the payload can perform any action available to the authenticated administrator, including modifying system templates, creating new administrative accounts, or exfiltrating session tokens. The design of the module ensures that moderation activity triggers the vulnerability, making it highly effective for attackers seeking to target administrative users.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability poses a critical risk to Contao installations, enabling unauthenticated remote attackers to gain administrative control over the application. Successful exploitation leads to full application compromise, as the attacker can leverage the administrative interface to inject malicious code into templates, resulting in server-side remote code execution. The scope of impact includes any Contao instance using the vulnerable versions of the comments-bundle, with no user interaction required beyond an administrator accessing the moderation interface.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Update the Contao comments-bundle to version 5.3.50 or later, or 5.7.12 or later, to incorporate necessary input sanitization.</li>
<li>Implement a strict Content-Security-Policy (CSP) on the back-end to mitigate the impact of potential XSS vulnerabilities until all components are updated.</li>
<li>Audit administrative logs for unexpected account creation or template modifications occurring in proximity to comment moderation activity.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>web-application</category><category>xss</category><category>cve</category></item></channel></rss>