GHSA-vq59-x6mq-4wgw
Dashboard / Vulnerabilities / GHSA-vq59-x6mq-4wgw
Summary: Contao SQL injection in the file manager
Details: David Wind, penetration tester with A1 Digital, has discovered that the SQL injection vulnerability originally published under CVE-2017-16558 can still be exploited in the file manager in Contao 4.
References: https://nvd.nist.gov/vuln/detail/CVE-2019-11512, https://github.com/contao/contao/commit/87d92f823b08b91a0aeb522284537c8afcdb8aba, https://contao.org/en/news/security-vulnerability-cve-2019-11512.html, https://github.com/FriendsOfPHP/security-advisories/blob/master/contao/contao/CVE-2019-11512.yaml, https://github.com/FriendsOfPHP/security-advisories/blob/master/contao/core-bundle/CVE-2019-11512.yaml
Affected packages
Package
Name: contao/contao
Purl: pkg:composer/contao/contao
Affected ranges
Type: ECOSYSTEM
Events:
