CVE-2024-28235

HIGH

Contao < 4.13.40 - Information Disclosure

Title source: rule
STIX 2.1

Description

Contao is an open source content management system. Starting in version 4.9.0 and prior to versions 4.13.40 and 5.3.4, when checking for broken links on protected pages, Contao sends the cookie header to external urls as well, the passed options for the http client are used for all requests. Contao versions 4.13.40 and 5.3.4 have a patch for this issue. As a workaround, disable crawling protected pages.

Scores

CVSS v3 8.3
EPSS 0.0041
EPSS Percentile 61.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (2)
contao/contao 4.9.0 - 4.13.40
contao/core-bundle 4.9.0 - 4.13.40Packagist
Published Apr 09, 2024
Tracked Since Feb 18, 2026