Contao 3.0.0 to 3.5.30 and 4.0.0 to 4.4.7 contains an SQL injection vulnerability in the back end as well as in the listing module.
Contao before 3.5.39 and 4.x before 4.7.3 has a Weak Password Recovery Mechanism for a Forgotten Password.
Contao 4.x allows SQL Injection. Fixed in Contao 4.4.39 and Contao 4.7.5.
Impact
Back end users with access to the file manager can upload malicious files and execute them on the server.
Patches
Update to Contao 4.13.49, 5.3.15 or 5.4.3.
Workarounds
Configure your web server so it does not execute PHP files and other scripts in the Contao file upload directory.
References
https://contao.org/en/security-advisories/remote-command-execution-through-file-uploads
For more information
If you have any questions or comments about this advisory, open an issue in contao/contao.
Credits
Thanks to Jakob Steeg from usd AG for reporting this vulnerability.
A logged in back end user can include arbitrary existing PHP files by manipulating an URL parameter
Impact
Authenticated users can inject malicious code in widgets with units, which is then executed both in the element preview (back end) and on the website (front end).
Patches
Update to Contao 4.9.42, 4.13.28 or 5.1.10.
Workarounds
Disable login for all untrusted back end users.
References
https://contao.org/en/security-advisories/cross-site-scripting-in-widgets-with-units
For more information
If you have any questions or comments about this advisory, open an issue in contao/contao.
Credits
Thanks to Christian Pöschl and Fabian Brenner from usd AG for reporting this vulnerability.
Contao before 4.5.7 has XSS in the system log.
Impact
It is possible for untrusted users to inject malicious code into HTML attributes in the back end, which will be executed both in the element preview (back end) and on the website (front end).
Installations are only affected if there are untrusted back end users who have the rights to modify HTML fields (e.g. TinyMCE).
Patches
Update to Contao 4.4.56, 4.9.18 or 4.11.7
Workarounds
Disable all fields that allow HTML for untrusted back end users or disable the login for these users.
References
https://contao.org/en/security-advisories/cross-site-scripting-via-html-attributes-in-the-back-end
For more information
If you have any questions or comments about this advisory, open an issue in contao/contao.
Credits
Thanks to Mikhail Khramenkov and Moritz Vondano for reporting this security issue.
Impact
Users can insert malicious code into file names when uploading files, which is then executed in tooltips and popups in the backend.
Patches
Update to Contao 4.13.40 or Contao 5.3.4.
Workarounds
Disable uploads for untrusted users.
References
https://contao.org/en/security-advisories/cross-site-scripting-in-the-file-manager
For more information
If you have any questions or comments about this advisory, open an issue in contao/contao.
Credits
Thanks to Alexander Wuttke for reporting this vulnerability.
Impact
It is possible to inject insert tags via the form generator if the submitted form data is output on the page in a specific way.
Patches
Update to Contao 4.13.40 or 5.3.4.
Workarounds
Do not output the submitted form data on the website.
References
https://contao.org/en/security-advisories/insert-tag-injection-via-the-form-generator
For more information
If you have any questions or comments about this advisory, open an issue in contao/contao.