Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v24p-7p4j-qvvf

Опубликовано: 09 апр. 2024
Источник: github
Github: Прошло ревью
CVSS3: 5.4

Описание

Contao: Cross site scripting in the file manager

Impact

Users can insert malicious code into file names when uploading files, which is then executed in tooltips and popups in the backend.

Patches

Update to Contao 4.13.40 or Contao 5.3.4.

Workarounds

Disable uploads for untrusted users.

References

https://contao.org/en/security-advisories/cross-site-scripting-in-the-file-manager

For more information

If you have any questions or comments about this advisory, open an issue in contao/contao.

Credits

Thanks to Alexander Wuttke for reporting this vulnerability.

Пакеты

Наименование

contao/core-bundle

composer
Затронутые версииВерсия исправления

>= 4.0.0, < 4.13.40

4.13.40

Наименование

contao/core-bundle

composer
Затронутые версииВерсия исправления

>= 5.0.0-RC1, < 5.3.4

5.3.4

EPSS

Процентиль: 80%
0.01402
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
почти 2 года назад

Contao is an open source content management system. Starting in version 4.0.0 and prior to version 4.13.40 and 5.3.4, users can inject malicious code in filenames when uploading files (back end and front end), which is then executed in tooltips and popups in the back end. Contao versions 4.13.40 and 5.3.4 have a patch for this issue. As a workaround, remove upload fields from frontend forms and disable uploads for untrusted back end users.

EPSS

Процентиль: 80%
0.01402
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79