PT-2021-21742 · Contao · Contao
Leofeyer
·
Published
2021-08-11
·
Updated
2021-08-23
·
CVE-2021-37627
CVSS v3.1
8.0
High
| Vector | AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Contao versions prior to 4.4.56
Contao versions prior to 4.9.18
Contao versions prior to 4.11.7
Description
Contao is an open source CMS that allows creation of websites and scalable web applications. In affected versions, it is possible to gain privileged rights in the Contao back end. This issue affects installations with untrusted back end users who have access to the form generator.
Recommendations
For versions prior to 4.4.56, update to Contao 4.4.56.
For versions prior to 4.9.18, update to Contao 4.9.18.
For versions prior to 4.11.7, update to Contao 4.11.7.
As a temporary workaround, consider disabling the form generator or disabling the login for untrusted back end users.
Exploit
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Contao