PT-2024-23305 · Contao · Contao
Bytehead
·
Published
2024-04-09
·
Updated
2025-01-09
·
CVE-2024-30262
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Contao versions prior to 4.13.40
Description
Contao is an open source content management system. When a frontend member changes their password in the personal data or the password lost module, the corresponding remember-me tokens are not removed. If someone compromises an account and is able to get a remember-me token, changing the password would not be enough to reclaim control over the account.
Recommendations
Update to Contao version 4.13.40 to resolve the issue.
As a temporary workaround, disable "Allow auto login" in the login module.
Exploit
Fix
Insufficient Session Expiration
Session Fixation
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Contao