PT-2021-3934 · Contao · Contao
Leofeyer
·
Published
2021-08-11
·
Updated
2021-08-23
·
CVE-2021-37626
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Contao versions prior to 4.4.56
Contao versions prior to 4.9.18
Contao versions prior to 4.11.7
Description
The issue is related to incorrect code generation management in Contao, allowing an attacker to load arbitrary PHP files via insert tags in the Contao back end. This can impact the confidentiality, integrity, and availability of protected information. Installations are only affected if they have untrusted back end users who have the rights to modify fields that are shown in the front end.
Recommendations
Update to Contao 4.4.56 to resolve the issue.
Update to Contao 4.9.18 to resolve the issue.
Update to Contao 4.11.7 to resolve the issue.
If you cannot update, disable the login for untrusted back end users as a temporary workaround.
Exploit
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Contao