logo

Database

Security controls bypass or absence In contao/core-bundle

Description

Contao is vulnerable to remote code execution in template closures

Impact

Backend users with precise control over the contents of template closures can execute arbitrary PHP functions that do not have required parameters.

Patches

Update to Contao 4.13.57, 5.3.42 or 5.6.5

Workarounds

Manually patch the Contao\Template::once() method.

Resources

https://contao.org/en/security-advisories/remote-code-execution-in-template-closures

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions