contao/core-bundle Security Advisories for 4.13.15 (9)
-
[MEDIUM] Contao affected by insert tag injection via canonical URL
PKSA-8psg-sb44-9n6y CVE-2024-45612 GHSA-2xpq-xp6c-5mgj
Affected version: >=5.4.0,<5.4.3|>=5.0.0,<5.3.15|>=4.13.0,<4.13.49
Reported by:
GitHub -
[MEDIUM] Contao affected by directory traversal in the file selector widget
PKSA-gkh9-zxxg-dpvd CVE-2024-45604 GHSA-4p75-5p53-65m9
Affected version: <4.13.49
Reported by:
GitHub -
[HIGH] Contao affected by remote command execution through file upload
PKSA-5k7g-byhd-8xrm CVE-2024-45398 GHSA-vm6r-j788-hjh5
Affected version: >=5.4.0,<5.4.3|>=5.0.0,<5.3.15|>=4.0.0,<4.13.49
Reported by:
GitHub -
[LOW] Contao: Unencoded insert tags in the frontend
PKSA-rk65-kfm6-21d9 CVE-2024-28191 GHSA-747v-52c4-8vj8
Affected version: >=5.0.0-RC1,<5.3.4|>=4.0.0,<4.13.40
Reported by:
GitHub -
[MEDIUM] Contao: Cross site scripting in the file manager
PKSA-bxmw-zt4x-f182 CVE-2024-28190 GHSA-v24p-7p4j-qvvf
Affected version: >=5.0.0-RC1,<5.3.4|>=4.0.0,<4.13.40
Reported by:
GitHub -
[MEDIUM] Contao: Remember-me tokens will not be cleared after a password change
PKSA-7hz7-f163-3mdr CVE-2024-30262 GHSA-r4r6-j2j3-7pp5
Affected version: <4.13.40
Reported by:
GitHub -
[HIGH] Contao: Possible cookie sharing with external domains while checking protected pages for broken links
PKSA-g1qg-mn7d-638g CVE-2024-28235 GHSA-9jh5-qf84-x6pr
Affected version: >=5.0.0-RC1,<5.3.4|>=4.9.0,<4.13.40
Reported by:
GitHub -
[MEDIUM] Cross site scripting via input unit widget
PKSA-kc45-s13v-qqqk CVE-2023-36806 GHSA-4gpr-p634-922x
Affected version: >=5.0.0,<5.1.10|>=4.10.0,<4.13.28|>=4.0.0,<4.9.42
Reported by:
GitHub -
Directory traversal vulnerability in the file manager
PKSA-wth6-rm9c-yh3w CVE-2023-29200
Affected version: >=4.9.0,<4.9.40|>=4.13.0,<4.13.21|>=5.1.0,<5.1.4
Reported by:
FriendsOfPHP/security-advisories