Confirming an opt-in token does not invalidate previous opt-in tokens
Contao 3.0.0 to 3.5.30 and 4.0.0 to 4.4.7 contains an SQL injection vulnerability in the back end as well as in the listing module.
Contao before 3.5.39 and 4.x before 4.7.3 has a Weak Password Recovery Mechanism for a Forgotten Password.
Contao 4.x allows SQL Injection. Fixed in Contao 4.4.39 and Contao 4.7.5.
Contao CMS through 3.2.4 has PHP Object Injection Vulnerabilities
Contao Managed Edition v1.5.0 was discovered to contain a remote command execution (RCE) vulnerability via the component phpcli parameter.
Impact
Back end users with access to the file manager can upload malicious files and execute them on the server.
Patches
Update to Contao 4.13.49, 5.3.15 or 5.4.3.
Workarounds
Configure your web server so it does not execute PHP files and other scripts in the Contao file upload directory.
References
https://contao.org/en/security-advisories/remote-command-execution-through-file-uploads
For more information
If you have any questions or comments about this advisory, open an issue in contao/contao.
Credits
Thanks to Jakob Steeg from usd AG for reporting this vulnerability.
Impact
A back end user with access to the form generator can upload arbitrary files and execute them on the server.
Patches
Update to Contao 4.4.46 or 4.8.6.
Workarounds
Configure your web server so it does not execute PHP files and other scripts in the Contao file upload directory.
References
https://contao.org/en/security-advisories/unrestricted-file-uploads
For more information
If you have any questions or comments about this advisory, open an issue in contao/contao.
A logged in back end user can include arbitrary existing PHP files by manipulating an URL parameter
Contao 4.7 allows CSRF.
Impact
If the crawler is set to crawl protected pages, it sends the cookie header to externals URLs.
Patches
Update to Contao 4.13.40 or 5.3.4.
Workarounds
Disable crawling protected pages.
References
https://contao.org/en/security-advisories/session-cookie-disclosure-in-the-crawler
For more information
If you have any questions or comments about this advisory, open an issue in contao/contao.
Impact
Untrusted users can inject malicious code into the canonical tag, which is then executed on the web page (front end).
Patches
Update to Contao 4.13.3.
Workarounds
Disable canonical tags in the root page settings.
References
https://contao.org/en/security-advisories/cross-site-scripting-via-canonical-url
For more information
If you have any questions or comments about this advisory, open an issue in contao/contao.
Impact
When a front end member changes their password, the corresponding remember-me tokens are not removed.
Patches
Update to Contao 4.13.40.
Workarounds
Disable "Allow auto login" in the login module.
References
https://contao.org/en/security-advisories/remember-me-tokens-are-not-cleared-after-a-password-change
For more information
If you have any questions or comments about this advisory, open an issue in contao/contao.
Multiple cross-site request forgery (CSRF) vulnerabilities in main.php in Contao (formerly TYPOlight) 2.11.0 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) delete users via a delete action in the user module, (2) delete news via a delete action in the news module, or (3) delete newsletters via a delete action in the newsletters module.
Impact
Authenticated users can inject malicious code in widgets with units, which is then executed both in the element preview (back end) and on the website (front end).
Patches
Update to Contao 4.9.42, 4.13.28 or 5.1.10.
Workarounds
Disable login for all untrusted back end users.
References
https://contao.org/en/security-advisories/cross-site-scripting-in-widgets-with-units
For more information
If you have any questions or comments about this advisory, open an issue in contao/contao.
Credits
Thanks to Christian Pöschl and Fabian Brenner from usd AG for reporting this vulnerability.
Contao is an open source content management system. Prior to versions 4.9.40, 4.13.21, and 5.1.4, logged in users can list arbitrary system files in the file manager by manipulating the Ajax request. However, it is not possible to read the contents of these files. Users should update to Contao 4.9.40, 4.13.21 or 5.1.4 to receive a patch. There are no known workarounds.
Contao 3.x before 3.5.37, 4.4.x before 4.4.31 and 4.6.x before 4.6.11 has Incorrect Access Control.
Impact
It is possible to inject code into the tllog table that will be executed in the browser when the system log is called in the back end.
Patches
Update to Contao 4.9.16 or 4.11.5.
Workarounds
Disable the system log module in the back end for all users (especially admin users).
References
https://contao.org/en/security-advisories/cross-site-scripting-in-the-system-log-2021
For more information
If you have any questions or comments about this advisory, open an issue in contao/contao.
Contao before 4.5.7 has XSS in the system log.
Contao 3.x before 3.5.32 allows Cross-site Scripting (XSS) via the unsubscribe module in the frontend newsletter extension.
Impact
It is possible for untrusted users to inject malicious code into HTML attributes in the back end, which will be executed both in the element preview (back end) and on the website (front end).
Installations are only affected if there are untrusted back end users who have the rights to modify HTML fields (e.g. TinyMCE).
Patches
Update to Contao 4.4.56, 4.9.18 or 4.11.7
Workarounds
Disable all fields that allow HTML for untrusted back end users or disable the login for these users.
References
https://contao.org/en/security-advisories/cross-site-scripting-via-html-attributes-in-the-back-end
For more information
If you have any questions or comments about this advisory, open an issue in contao/contao.
Credits
Thanks to Mikhail Khramenkov and Moritz Vondano for reporting this security issue.
Impact
Users can insert malicious code into file names when uploading files, which is then executed in tooltips and popups in the backend.
Patches
Update to Contao 4.13.40 or Contao 5.3.4.
Workarounds
Disable uploads for untrusted users.
References
https://contao.org/en/security-advisories/cross-site-scripting-in-the-file-manager
For more information
If you have any questions or comments about this advisory, open an issue in contao/contao.
Credits
Thanks to Alexander Wuttke for reporting this vulnerability.
Impact
It is possible to inject insert tags via the form generator if the submitted form data is output on the page in a specific way.
Patches
Update to Contao 4.13.40 or 5.3.4.
Workarounds
Do not output the submitted form data on the website.
References
https://contao.org/en/security-advisories/insert-tag-injection-via-the-form-generator
For more information
If you have any questions or comments about this advisory, open an issue in contao/contao.
Impact
It is possible to inject insert tags in canonical URLs which will be replaced when the page is rendered.
Patches
Update to Contao 4.13.49, 5.3.15 or 5.4.3.
Workarounds
Disable canonical tags in the settings of the website root page.
References
https://contao.org/en/security-advisories/insert-tag-injection-via-canonical-urls
For more information
If you have any questions or comments about this advisory, open an issue in contao/contao.
Impact
It is possible to inject insert tags in front end forms which will be replaced when the page is rendered.
Patches
Update to Contao 4.4.52, 4.9.6 or 4.10.1.
Workarounds
Disable the front end login form and do not use form fields with array keys such as fieldname[].
References
https://contao.org/en/security-advisories/insert-tag-injection-in-forms
For more information
If you have any questions or comments about this advisory, open an issue in contao/contao.
Impact
It is possible to inject insert tags into the login module which will be replaced when the page is rendered.
Patches
Update to Contao 4.8.6.
Workarounds
None.
References
https://contao.org/en/security-advisories/insert-tag-injection-in-the-login-module
For more information
If you have any questions or comments about this advisory, open an issue in contao/contao.
Impact
Back end users can manipulate the details view URL to show pages and articles that have not been enabled for them.
Patches
Update to Contao 4.4.46 or 4.8.6.
Workarounds
None.
References
https://contao.org/en/security-advisories/information-disclosure-in-the-back-end
For more information
If you have any questions or comments about this advisory, open an issue in contao/contao.
Impact
If BBCode is enabled for comments, users can inject CSS styles.
Patches
Update to Contao 4.13.40 or 5.3.4.
Workarounds
Disable BBCode for comments.
References
https://contao.org/en/security-advisories/insufficient-bbcode-sanitization
For more information
If you have any questions or comments about this advisory, open an issue in contao/contao.
Impact
Back end users can list files outside their file mounts or the document root in the FileSelector widget.
Patches
Update to Contao 4.13.49.
Workarounds
None.
References
https://contao.org/en/security-advisories/directory-traversal-in-the-fileselector-widget
For more information
If you have any questions or comments about this advisory, open an issue in contao/contao.
Credits
Thanks to Jakob Steeg from usd AG for reporting this vulnerability.
A directory traversal vulnerability allows back end users to view files outside their document root