logo

Database

Server side template injection In contao/core

Description

contao/core PHP object injection vulnerability allows for arbitrary code execution PHP object injection vulnerability was identified in contao/core due to untrusted data being passed to deserialize() function.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions