VDB
Sign up
CRITICAL9.0

GHSA-wxxw-5gq6-j2g5

contao/core Insufficient input validation allows for code injection and remote execution

Quick fix

GHSA-wxxw-5gq6-j2g5 — contao/core: upgrade to the fixed version with the command below.

composer require contao/core:^2.11.17

Details

contao/core versions 2.x prior to 2.11.17 and 3.x prior to 3.2.9 are vulnerable to arbitrary code execution on the server due to insufficient input validation. In fact, attackers can remove or change pathconfig.php by entering a URL, meaning that the entire Contao installation will no longer be accessible or malicious code can be executed.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/contao/core
Introduced in: 2.0.0Fixed in: 2.11.17
Fixcomposer require contao/core:^2.11.17
Packagist/contao/core
Introduced in: 3.0.0Fixed in: 3.2.9
Fixcomposer require contao/core:^3.2.9

References