CVE-2024-28190: Contao core bundle vulnerable to cross site scripting in the file manager
Impact
Users can insert malicious code into file names when uploading files, which is then executed in tooltips and popups in the backend.
Patches
Update to Contao 4.13.40 or Contao 5.3.4.
Workarounds
Disable uploads for untrusted users.
References
https://contao.org/en/security-advisories/cross-site-scripting-in-the-file-manager
For more information
If you have any questions or comments about this advisory, open an issue in contao/contao.
Credits
Thanks to Alexander Wuttke for reporting this vulnerability.
Other sources
Contao is an open source content management system. Starting in version 4.0.0 and prior to version 4.13.40 and 5.3.4, users can inject malicious code in filenames when uploading files (back end and front end), which is then executed in tooltips and popups in the back end. Contao versions 4.13.40 and 5.3.4 have a patch for this issue. As a workaround, remove upload fields from frontend forms and disable uploads for untrusted back end users.
— NVD
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-28190?
CVE-2024-28190 has a moderate severity level due to the potential for execution of malicious code through file uploads.
How do I fix CVE-2024-28190?
To resolve CVE-2024-28190, update to Contao version 4.13.40 or 5.3.4.
What are the workarounds for CVE-2024-28190?
A temporary workaround for CVE-2024-28190 is to disable uploads for untrusted users.
What is CVE-2024-28190?
CVE-2024-28190 is a vulnerability that allows users to inject malicious code into file names during file uploads.
Which versions of Contao are affected by CVE-2024-28190?
CVE-2024-28190 affects Contao versions prior to 4.13.40 and 5.3.4.