VDB
Sign up
HIGH

GHSA-wq43-8r5p-w3mc

contao/core PHP object injection vulnerability allows for arbitrary code execution

Quick fix

GHSA-wq43-8r5p-w3mc — contao/core: upgrade to the fixed version with the command below.

composer require contao/core:^2.11.14

Details

PHP object injection vulnerability was identified in contao/core due to untrusted data being passed to `deserialize()` function.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/contao/core
Introduced in: 2.0.0Fixed in: 2.11.14
Fixcomposer require contao/core:^2.11.14
Packagist/contao/core
Introduced in: 3.0.0Fixed in: 3.2.5
Fixcomposer require contao/core:^3.2.5

References