CVE-2024-30262: Contao's remember-me tokens will not be cleared after a password change
Impact
When a front end member changes their password, the corresponding remember-me tokens are not removed.
Patches
Update to Contao 4.13.40.
Workarounds
Disable "Allow auto login" in the login module.
References
https://contao.org/en/security-advisories/remember-me-tokens-are-not-cleared-after-a-password-change
For more information
If you have any questions or comments about this advisory, open an issue in contao/contao.
Other sources
Contao is an open source content management system. Prior to version 4.13.40, when a frontend member changes their password in the personal data or the password lost module, the corresponding remember-me tokens are not removed. If someone compromises an account and is able to get a remember-me token, changing the password would not be enough to reclaim control over the account. Version 4.13.40 contains a fix for the issue. As a workaround, disable "Allow auto login" in the login module.
— NVD
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-30262?
CVE-2024-30262 is a moderate severity vulnerability that allows remember-me tokens to persist even after a user changes their password.
How do I fix CVE-2024-30262?
To fix CVE-2024-30262, update to Contao version 4.13.40 or later.
What are the potential risks of CVE-2024-30262?
The risks include unauthorized access to user accounts due to tokens not being invalidated after a password change.
Can I use a workaround for CVE-2024-30262?
Yes, as a temporary workaround, you can disable the 'Allow auto login' feature in the login module.
What software versions are affected by CVE-2024-30262?
CVE-2024-30262 affects all versions of Contao prior to 4.13.40.