CVE-2018-20028: Medium severity contao cms vulnerability
Published Apr 17, 2019
·Updated
Contao 3.x before 3.5.37, 4.4.x before 4.4.31 and 4.6.x before 4.6.11 has Incorrect Access Control.
Affected Software
6 affected componentsFixes available
composer/contao/contao>=4.4.0<4.4.31
4.4.31
composer/contao/contao>=4.6.0<4.6.11
4.6.11
composer/contao/contao>=3.0.0<3.5.37
3.5.37
Contao Contao CMS>=3.0.0<3.5.37
Contao Contao CMS>=4.4.0<4.4.31
Contao Contao CMS>=4.6.0<4.6.11
Event History
Apr 17, 2019
CVE Published
via MITRE·06:58 PM
Data Sourced
via MITRE·06:58 PM
Description
May 13, 2022
Advisory Published
via GitHub·01:19 AM
Frequently Asked Questions
1
What is the vulnerability ID for this Contao issue?
The vulnerability ID for this Contao issue is CVE-2018-20028.
2
What is the severity level of CVE-2018-20028?
CVE-2018-20028 has a severity level of medium (6.5).
3
What is the issue with Contao 3.x, 4.4.x, and 4.6.x versions?
Contao 3.x before 3.5.37, 4.4.x before 4.4.31, and 4.6.x before 4.6.11 have an Incorrect Access Control vulnerability.
4
How does the Incorrect Access Control vulnerability impact Contao CMS?
The Incorrect Access Control vulnerability in Contao CMS allows unauthorized access to restricted functionality.
5
How can I fix the Incorrect Access Control vulnerability in Contao CMS?
To fix the Incorrect Access Control vulnerability, update Contao CMS to version 3.5.37, 4.4.31, or 4.6.11 or later.