Contao 是一款开源内容管理系统(CMS)。在版本 5.0.0 至 5.3.50 以及 5.7.12 之前,ImagesController 使用 Path::join() 将用户可控的 {path} 参数与配置的图片目标目录进行拼接,但未使用 Path::isBasePath() 验证最终规范化路径是否仍位于该目录之内。因此,攻击者可通过构造包含编码后的父目录段(如 “../”)的未认证请求,使 BinaryFileResponse 返回项目目录下任意允许扩展名(由 contao.image.valid_ex
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107845 | 9.3 CRITICAL | Contao: Cross-site scripting in the comments bundle |
| CVE-2026-107842 | 5.3 MEDIUM | Contao: Protected page content is disclosed to anonymous visitors after contao.search.inde |
| CVE-2026-107843 | 5.3 MEDIUM | Contao: The registration module re-sends activation mails on any unauthenticated POST, wit |
| CVE-2026-107851 | 4.3 MEDIUM | Contao: Improper access control in the table access voter |
| CVE-2026-107850 | 4.3 MEDIUM | Contao: Improper access control in the preview links module |
| CVE-2026-107848 | 3.5 LOW | Contao: Cross-site request forgery in custom backend actions |
No comments yet