Логотип exploitDog
bind:CVE-2024-28235
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-28235

Количество 2

Количество 2

nvd логотип

CVE-2024-28235

почти 2 года назад

Contao is an open source content management system. Starting in version 4.9.0 and prior to versions 4.13.40 and 5.3.4, when checking for broken links on protected pages, Contao sends the cookie header to external urls as well, the passed options for the http client are used for all requests. Contao versions 4.13.40 and 5.3.4 have a patch for this issue. As a workaround, disable crawling protected pages.

CVSS3: 8.3
EPSS: Низкий
github логотип

GHSA-9jh5-qf84-x6pr

почти 2 года назад

Contao: Possible cookie sharing with external domains while checking protected pages for broken links

CVSS3: 8.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-28235

Contao is an open source content management system. Starting in version 4.9.0 and prior to versions 4.13.40 and 5.3.4, when checking for broken links on protected pages, Contao sends the cookie header to external urls as well, the passed options for the http client are used for all requests. Contao versions 4.13.40 and 5.3.4 have a patch for this issue. As a workaround, disable crawling protected pages.

CVSS3: 8.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-9jh5-qf84-x6pr

Contao: Possible cookie sharing with external domains while checking protected pages for broken links

CVSS3: 8.3
0%
Низкий
почти 2 года назад

Уязвимостей на страницу