CVE-2024-28190: medium-severity vulnerability in contao
Contao core bundle vulnerable to cross site scripting in the file manager
Published · Updated
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.4epss 0.5%
exploitation probability
0.5%top 59% of all CVEs
observed exploitation
nono source reports it
Contao is an open source content management system. Starting in version 4.0.0 and prior to version 4.13.40 and 5.3.4, users can inject malicious code in filenames when uploading files (back end and front end), which is then executed in tooltips and popups in the back end. Contao versions 4.13.40 and 5.3.4 have a patch for this issue. As a workaround, remove upload fields from frontend forms and disable uploads for untrusted back end users.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Affected products
contao · contaoRelated CVEs — contao
In the same product, most dangerous first.
CVE-2022-24899HIGHCross site scripting via canonical tagEPSS 4.5%CVE-2021-37626HIGHPHP file inclusion via insert tagsEPSS 1.3%CVE-2021-37627HIGHPrivilege escalation via form generatorEPSS 1.0%CVE-2012-4383—CVE-2012-4383EPSS 0.9%CVE-2023-29200MEDIUMcontao/core-bundle has path traversal vulnerability in the file managerEPSS 0.8%CVE-2024-28235HIGHContao possible cookie sharing with external domains while checking protected pages for broken linksEPSS 0.7%
References
https://contao.org/en/security-advisories/cross-site-scripting-in-the-file-managerhttps://github.com/contao/contao/commit/878d28dbe0f408740555d6fc8b634bd3f8febfcehttps://github.com/contao/contao/commit/b794e14fff070101bf6a885da9b1a83395093b4dhttps://github.com/contao/contao/security/advisories/GHSA-v24p-7p4j-qvvf