Impact
A back end user with access to the form generator can upload arbitrary files and execute them on the server.
Patches
Update to Contao 4.4.46 or 4.8.6.
Workarounds
Configure your web server so it does not execute PHP files and other scripts in the Contao file upload directory.
References
https://contao.org/en/security-advisories/unrestricted-file-uploads
For more information
If you have any questions or comments about this advisory, open an issue in contao/contao.
Impact
It is possible to inject insert tags into the login module which will be replaced when the page is rendered.
Patches
Update to Contao 4.8.6.
Workarounds
None.
References
https://contao.org/en/security-advisories/insert-tag-injection-in-the-login-module
For more information
If you have any questions or comments about this advisory, open an issue in contao/contao.
Impact
Back end users can manipulate the details view URL to show pages and articles that have not been enabled for them.
Patches
Update to Contao 4.4.46 or 4.8.6.
Workarounds
None.
References
https://contao.org/en/security-advisories/information-disclosure-in-the-back-end
For more information
If you have any questions or comments about this advisory, open an issue in contao/contao.