CVE-2024-30262

MEDIUM

Contao <4.13.40 - Info Disclosure

Title source: llm
STIX 2.1

Description

Contao is an open source content management system. Prior to version 4.13.40, when a frontend member changes their password in the personal data or the password lost module, the corresponding remember-me tokens are not removed. If someone compromises an account and is able to get a remember-me token, changing the password would not be enough to reclaim control over the account. Version 4.13.40 contains a fix for the issue. As a workaround, disable "Allow auto login" in the login module.

Scores

CVSS v3 5.9
EPSS 0.0036
EPSS Percentile 58.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-613 CWE-384
Status published
Products (2)
contao/contao < 4.13.40
contao/core-bundle 0 - 4.13.40Packagist
Published Apr 09, 2024
Tracked Since Feb 18, 2026