VDB
Sign up
HIGH8.8

GHSA-9jq2-jvwc-p52f

Contao core SQL Injection Vulnerability

Quick fix

GHSA-9jq2-jvwc-p52f — contao/core: upgrade to the fixed version with the command below.

composer require contao/core:^2.11.4

Details

Contao core prior to 2.11.4 has a SQL injection vulnerability in `contao-2.11.3\system\modules\backend\Ajax.php`

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/contao/core
Introduced in: 0Fixed in: 2.11.4
Fixcomposer require contao/core:^2.11.4

References