PT-2019-9971 · Contao · Contao

Leo Feyer

·

Publicado

2019-04-17

·

Atualizado

2022-05-13

·

CVE-2018-20028

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Contao versions 3.x through 3.5.36 Contao versions 4.4.x through 4.4.30 Contao versions 4.6.x through 4.6.10
Description The issue is related to Incorrect Access Control, which can potentially allow unauthorized access to certain resources or functionality.
Recommendations For Contao versions 3.x through 3.5.36, update to version 3.5.37 or later. For Contao versions 4.4.x through 4.4.30, update to version 4.4.31 or later. For Contao versions 4.6.x through 4.6.10, update to version 4.6.11 or later.

Correção

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-20028
GHSA-Q99W-J4MJ-7HJ8

Produtos afetados

Contao