First published: Tue Apr 30 2019(Updated: )
Contao 4.x allows SQL Injection. Fixed in Contao 4.4.39 and Contao 4.7.5.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/contao/core-bundle | >=4.1.0<4.4.39>=4.5.0<4.6.0>=4.6.0<4.7.0>=4.7.0<4.7.5 | |
composer/contao/contao | >=4.1.0<4.4.39>=4.5.0<4.6.0>=4.6.0<4.7.0>=4.7.0<4.7.5 | |
Contao Contao | >=4.0.0<4.4.39 | |
Contao Contao | >=4.5.0<4.7.5 | |
composer/contao/core-bundle | >=4.5.0<4.7.5 | 4.7.5 |
composer/contao/core-bundle | >=4.1.0<4.4.39 | 4.4.39 |
composer/contao/contao | >=4.5.0<4.7.5 | 4.7.5 |
composer/contao/contao | >=4.1.0<4.4.39 | 4.4.39 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-11512 is a SQL injection vulnerability in Contao 4.x.
CVE-2019-11512 has a severity level of 9.8 (Critical).
CVE-2019-11512 affects Contao versions from 4.1.0 to 4.7.5.
CVE-2019-11512 can be fixed by upgrading Contao to version 4.4.39 or 4.7.5.
You can find more information about CVE-2019-11512 at https://contao.org/en/news/security-vulnerability-cve-2019-11512.html.