Vulnerabilities
Vulnerable Software
Contao:  >> Contao  >> 4.10.1  Security Vulnerabilities
Contao is an open source content management system. Prior to versions 4.9.40, 4.13.21, and 5.1.4, logged in users can list arbitrary system files in the file manager by manipulating the Ajax request. However, it is not possible to read the contents of these files. Users should update to Contao 4.9.40, 4.13.21 or 5.1.4 to receive a patch. There are no known workarounds.
CVSS Score
4.3
EPSS Score
0.003
Published
2023-04-25
Contao >=4.0.0 allows backend XSS via HTML attributes to an HTML field. Fixed in 4.4.56, 4.9.18, 4.11.7.
CVSS Score
4.8
EPSS Score
0.003
Published
2021-08-12
Contao 4.5.x through 4.9.x before 4.9.16, and 4.10.x through 4.11.x before 4.11.5, allows XSS. It is possible to inject code into the tl_log table that will be executed in the browser when the system log is called in the back end.
CVSS Score
6.1
EPSS Score
0.003
Published
2021-06-23


Contact Us

Shodan ® - All rights reserved