PT-2024-22350 · Contao · Contao
Leofeyer
·
Published
2024-04-09
·
Updated
2025-01-17
·
CVE-2024-28235
CVSS v3.1
8.3
High
| Vector | AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Contao versions 4.9.0 through 4.13.39
Contao versions 5.0.0 through 5.3.3
Description
The issue arises when checking for broken links on protected pages, causing Contao to send the cookie header to external URLs. The passed options for the HTTP client are used for all requests.
Recommendations
For Contao versions 4.9.0 through 4.13.39, update to Contao 4.13.40.
For Contao versions 5.0.0 through 5.3.3, update to Contao 5.3.4.
As a temporary workaround for all affected versions, consider disabling crawling protected pages to minimize the risk of exploitation.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Contao