CVE-2021-37626: PHP file inclusion via insert tags
Impact
It is possible for untrusted users to load arbitrary PHP files via insert tags.
Installations are only affected if there are untrusted back end users.
Patches
Update to Contao 4.4.56, 4.9.18 or 4.11.7.
Workarounds
Disable the login for untrusted back end users.
References
https://contao.org/en/security-advisories/php-file-inclusion-via-insert-tags
For more information
If you have any questions or comments about this advisory, open an issue in contao/contao.
Other sources
Contao is an open source CMS that allows you to create websites and scalable web applications. In affected versions it is possible to load PHP files by entering insert tags in the Contao back end. Installations are only affected if they have untrusted back end users who have the rights to modify fields that are shown in the front end. Update to Contao 4.4.56, 4.9.18 or 4.11.7 to resolve. If you cannot update then disable the login for untrusted back end users.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/contao/contaoto a version that resolves this vulnerability.Fixed in 4.11.7 - Upgrade
Upgrade
composer/contao/contaoto a version that resolves this vulnerability.Fixed in 4.9.18 - Upgrade
Upgrade
composer/contao/contaoto a version that resolves this vulnerability.Fixed in 4.4.56 - Upgrade
Upgrade
composer/contao/core-bundleto a version that resolves this vulnerability.Fixed in 4.11.7 - Upgrade
Upgrade
composer/contao/core-bundleto a version that resolves this vulnerability.Fixed in 4.9.18 - Upgrade
Upgrade
composer/contao/core-bundleto a version that resolves this vulnerability.Fixed in 4.4.56 - Upgrade
Upgrade
Contaoto a version that resolves this vulnerability.Fixed in 4.4.56 - Upgrade
Upgrade
Contaoto a version that resolves this vulnerability.Fixed in 4.9.18 - Upgrade
Upgrade
Contaoto a version that resolves this vulnerability.Fixed in 4.11.7 - Configuration
Disable the login for untrusted back end users (installations are affected only if there are untrusted back end users). If you cannot update to Contao 4.4.56, 4.9.18, or 4.11.7, disable this login setting.
Contao back end login for untrusted back end users = disabled
Event History
Frequently Asked Questions
What is CVE-2021-37626?
CVE-2021-37626 is a vulnerability in Contao that allows file inclusion via insert tags in the Contao back end.
How severe is CVE-2021-37626?
CVE-2021-37626 has a severity rating of 7.2 (High).
Which versions of Contao are affected by CVE-2021-37626?
Versions between 4.0.0 and 4.4.56, 4.5.0 and 4.6.0, 4.6.0 and 4.7.0, 4.7.0 and 4.8.0, 4.8.0 and 4.9.0, 4.9.0 and 4.9.18, 4.10.0 and 4.11.0, 4.11.0 and 4.11.7 of Contao are affected by CVE-2021-37626.
How can I fix CVE-2021-37626?
To fix CVE-2021-37626, it is recommended to update Contao to a version that is not affected by the vulnerability.
Where can I find more information about CVE-2021-37626?
You can find more information about CVE-2021-37626 in the Contao security advisories and the GitHub security advisory.