Contao是Contao开源的一套采用PHP开发的开源内容管理系统(CMS)。该系统支持搜索引擎、权限管理和CSS框架等。 Contao 4.13.0及之前版本存在输入验证错误漏洞,该漏洞源于未受信任的用户可以在规范标签中注入插入标签,这些标签随后在网页前端被替换。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-45398 | 8.3 HIGH | Remote command execution through file upload in contao/core-bundle |
| CVE-2024-45604 | 4.3 MEDIUM | Directory traversal in the file selector widget in contao/core-bundle |
No comments yet