CVE-2012-4383: SQL Injection
Published Jan 29, 2020
·Updated
Contao core prior to 2.11.4 has a SQL injection vulnerability in contao-2.11.3\system\modules\backend\Ajax.php
Other sources
contao prior to 2.11.4 has a sql injection vulnerability
Affected Software
2 affected componentsFixes available
composer/contao/core<2.11.4
2.11.4
Contao Contao<2.11.4
Remediation
Patch Available
Event History
Jan 29, 2020
CVE Published
via MITRE·02:42 PM
Data Sourced
via MITRE·02:42 PM
DescriptionWeakness
Apr 23, 2022
Advisory Published
via GitHub·12:40 AM
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2012-4383.
2
What is the severity of CVE-2012-4383?
The severity of CVE-2012-4383 is high with a CVSS score of 8.8.
3
What is the affected software?
The affected software is Contao prior to version 2.11.4.
4
How does CVE-2012-4383 affect the software?
CVE-2012-4383 allows an attacker to execute SQL injection attacks on Contao prior to version 2.11.4.
5
How can I mitigate CVE-2012-4383?
To mitigate CVE-2012-4383, you should update Contao to version 2.11.4 or later.