CVE-2024-28190 Information
Description
Contao is an open source content management system. Starting in version 4.0.0 and prior to version 4.13.40 and 5.3.4 users can inject malicious code in filenames when uploading files (back end and front end) which is then executed in tooltips and popups in the back end. Contao versions 4.13.40 and 5.3.4 have a patch for this issue. As a workaround remove upload fields from frontend forms and disable uploads for untrusted back end users.
Reference
https://github.com/contao/contao/security/advisories/GHSA-v24p-7p4j-qvvf https://github.com/contao/contao/commit/878d28dbe0f408740555d6fc8b634bd3f8febfce https://github.com/contao/contao/commit/b794e14fff070101bf6a885da9b1a83395093b4d https://contao.org/en/security-advisories/cross-site-scripting-in-the-file-manager
Share on: