PT-2021-21742 · Contao · Contao

Leofeyer

·

Published

2021-08-11

·

Updated

2021-08-23

·

CVE-2021-37627

CVSS v3.1

8.0

High

VectorAV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Contao versions prior to 4.4.56 Contao versions prior to 4.9.18 Contao versions prior to 4.11.7
Description Contao is an open source CMS that allows creation of websites and scalable web applications. In affected versions, it is possible to gain privileged rights in the Contao back end. This issue affects installations with untrusted back end users who have access to the form generator.
Recommendations For versions prior to 4.4.56, update to Contao 4.4.56. For versions prior to 4.9.18, update to Contao 4.9.18. For versions prior to 4.11.7, update to Contao 4.11.7. As a temporary workaround, consider disabling the form generator or disabling the login for untrusted back end users.

Exploit

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-37627
GHSA-HQ5M-MQMX-FW6M

Affected Products

Contao