PT-2019-12345 · Contao · Contao

David Wind

·

Published

2019-07-09

·

Updated

2022-05-24

·

CVE-2019-11512

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Contao versions prior to 4.4.39 Contao versions prior to 4.7.5
Description The issue allows SQL Injection. A penetration tester discovered that the SQL injection vulnerability can still be exploited in the file manager in Contao 4.
Recommendations For Contao versions prior to 4.4.39, update to Contao 4.4.39 or later. For Contao versions prior to 4.7.5, update to Contao 4.7.5 or later.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-11512
GHSA-VQ59-X6MQ-4WGW

Affected Products

Contao