SQL injection - Code In contao/contao
Description
Contao SQL injection in the file manager David Wind, penetration tester with A1 Digital, has discovered that the SQL injection vulnerability originally published under CVE-2017-16558 can still be exploited in the file manager in Contao 4.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
packagist | 4.4.39, 4.7.5 | ||
packagist | 4.4.39, 4.7.5 |
Aliases
1. 2. 3. 4.
References
1. 2. 3. 4.