PT-2023-25700 · Contao · Contao

Christian Pöschl

+1

·

Publicado

2023-07-25

·

Atualizado

2023-11-15

·

CVE-2023-36806

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Contao versions 4.0.0 through 4.9.41 Contao versions 4.13.0 through 4.13.27 Contao versions 5.0.0 through 5.1.9
Description Contao is an open source content management system. It is possible for untrusted backend users to inject malicious code into headline fields in the back end, which will be executed both in the element preview and on the website. Installations are only affected if there are untrusted back end users who have the rights to modify headline fields, or other fields using the input unit widget.
Recommendations For Contao versions 4.0.0 through 4.9.41, update to Contao 4.9.42. For Contao versions 4.13.0 through 4.13.27, update to Contao 4.13.28. For Contao versions 5.0.0 through 5.1.9, update to Contao 5.1.10. As a temporary workaround, consider disabling the login for all untrusted back end users.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-36806
GHSA-4GPR-P634-922X

Produtos afetados

Contao