PT-2024-40514 · Contao · Contao/Core

Published

2024-05-15

·

Updated

2024-05-15

CVSS v3.1

9.0

Critical

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions contao/core versions 2.x prior to 2.11.17 contao/core versions 3.x prior to 3.2.9
Description The issue is related to arbitrary code execution on the server due to insufficient input validation. Attackers can exploit this by entering a specific URL, which allows them to remove or change pathconfig.php. This can result in the Contao installation becoming inaccessible or malicious code being executed.
Recommendations For contao/core versions 2.x prior to 2.11.17, update to version 2.11.17 or later. For contao/core versions 3.x prior to 3.2.9, update to version 3.2.9 or later.

Fix

Related Identifiers

GHSA-WXXW-5GQ6-J2G5

Affected Products

Contao/Core