CVE-2017-16558

CRITICAL

Contao <3.5.30, <4.4.7 - SQL Injection

Title source: llm
STIX 2.1

Description

Contao 3.0.0 to 3.5.30 and 4.0.0 to 4.4.7 contains an SQL injection vulnerability in the back end as well as in the listing module.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_confirm
https://contao.org/de/changelog/versions/4.4.html
Vendor Advisory x_refsource_confirm
https://contao.org/en/news/contao-4_4_8.html

Scores

CVSS v3 9.8
EPSS 0.0118
EPSS Percentile 64.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (4)
contao/contao 3.0.0Packagist
contao/contao_cms 3.0.0 - 3.5.30
contao/core-bundle 4.0.0 - 4.4.8Packagist
contao/listing-bundle 4.0.0 - 4.4.8Packagist
Published Apr 25, 2019
Tracked Since Feb 18, 2026