title: Cross-site scripting (XSS) vulnerability in the system log of the back end
link: https://contao.org/en/news/contao-4_4_18.html
cve: CVE-2018-10125
branches:
4.x:
time: 2018-04-18 09:23:00
versions: ['>=4.0.0', '<4.4.18']
4.5.x:
time: 2018-04-18 09:29:00
versions: ['>=4.5.0', '<4.5.8']
reference: composer://contao/core-bundle