PT-2021-3934 · Contao · Contao

Leofeyer

·

Published

2021-08-11

·

Updated

2021-08-23

·

CVE-2021-37626

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Contao versions prior to 4.4.56 Contao versions prior to 4.9.18 Contao versions prior to 4.11.7
Description The issue is related to incorrect code generation management in Contao, allowing an attacker to load arbitrary PHP files via insert tags in the Contao back end. This can impact the confidentiality, integrity, and availability of protected information. Installations are only affected if they have untrusted back end users who have the rights to modify fields that are shown in the front end.
Recommendations Update to Contao 4.4.56 to resolve the issue. Update to Contao 4.9.18 to resolve the issue. Update to Contao 4.11.7 to resolve the issue. If you cannot update, disable the login for untrusted back end users as a temporary workaround.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-04451
CVE-2021-37626
GHSA-R6MV-PPJC-4HGR

Affected Products

Contao