PT-2024-23305 · Contao · Contao

Bytehead

·

Published

2024-04-09

·

Updated

2025-01-09

·

CVE-2024-30262

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Contao versions prior to 4.13.40
Description Contao is an open source content management system. When a frontend member changes their password in the personal data or the password lost module, the corresponding remember-me tokens are not removed. If someone compromises an account and is able to get a remember-me token, changing the password would not be enough to reclaim control over the account.
Recommendations Update to Contao version 4.13.40 to resolve the issue. As a temporary workaround, disable "Allow auto login" in the login module.

Exploit

Fix

Insufficient Session Expiration

Session Fixation

Weakness Enumeration

Related Identifiers

CVE-2024-30262
GHSA-R4R6-J2J3-7PP5

Affected Products

Contao