PT-2022-17751 · Contao · Contao Managed Edition
Published
2022-03-18
·
Updated
2023-08-08
·
CVE-2022-26265
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Contao Managed Edition version 1.5.0
Description
A remote command execution issue was discovered, allowing for potential exploitation via the
php cli parameter. This could lead to unauthorized execution of commands.Recommendations
For Contao Managed Edition version 1.5.0, consider disabling the
php cli parameter as a temporary workaround until a patch is available. Restrict access to the component utilizing the php cli parameter to minimize the risk of exploitation.Exploit
Fix
RCE
OS Command Injection
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Contao Managed Edition