Логотип exploitDog
bind:CVE-2025-65960
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-65960

Количество 2

Количество 2

nvd логотип

CVE-2025-65960

3 месяца назад

Contao is an Open Source CMS. From version 4.0.0 to before 4.13.57, before 5.3.42, and before 5.6.5, back end users with precise control over the contents of template closures can execute arbitrary PHP functions that do not have required parameters. This issue has been patched in versions 4.13.57, 5.3.42, and 5.6.5. A workaround for this issue involves manually patching the Contao\Template::once() method.

CVSS3: 6.6
EPSS: Низкий
github логотип

GHSA-98vj-mm79-v77r

3 месяца назад

Contao is vulnerable to remote code execution in template closures

CVSS3: 6.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-65960

Contao is an Open Source CMS. From version 4.0.0 to before 4.13.57, before 5.3.42, and before 5.6.5, back end users with precise control over the contents of template closures can execute arbitrary PHP functions that do not have required parameters. This issue has been patched in versions 4.13.57, 5.3.42, and 5.6.5. A workaround for this issue involves manually patching the Contao\Template::once() method.

CVSS3: 6.6
0%
Низкий
3 месяца назад
github логотип
GHSA-98vj-mm79-v77r

Contao is vulnerable to remote code execution in template closures

CVSS3: 6.6
0%
Низкий
3 месяца назад

Уязвимостей на страницу