PT-2024-22350 · Contao · Contao

Leofeyer

·

Published

2024-04-09

·

Updated

2025-01-17

·

CVE-2024-28235

CVSS v3.1

8.3

High

VectorAV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Contao versions 4.9.0 through 4.13.39 Contao versions 5.0.0 through 5.3.3
Description The issue arises when checking for broken links on protected pages, causing Contao to send the cookie header to external URLs. The passed options for the HTTP client are used for all requests.
Recommendations For Contao versions 4.9.0 through 4.13.39, update to Contao 4.13.40. For Contao versions 5.0.0 through 5.3.3, update to Contao 5.3.4. As a temporary workaround for all affected versions, consider disabling crawling protected pages to minimize the risk of exploitation.

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2024-28235
GHSA-9JH5-QF84-X6PR

Affected Products

Contao