CVE-2017-16558SQL Injection in Contao

CWE-89SQL Injection6 documents4 sources
Severity
9.8CRITICALNVD
EPSS
0.3%
top 47.72%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 25
Latest updateMay 24

Description

Contao 3.0.0 to 3.5.30 and 4.0.0 to 4.4.7 contains an SQL injection vulnerability in the back end as well as in the listing module.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages4 packages

Packagistcontao/listing-bundle4.0.04.4.8+1
Packagistcontao/contao4.1.04.4.39+3
Packagistcontao/core-bundle4.1.04.4.39+3
NVDcontao/contao_cms3.0.03.5.30+1

🔴Vulnerability Details

5
OSV
Contao SQL injection in the file manager2022-05-24
OSV
Contao SQL injection in the backend and listing module2022-05-24
GHSA
Contao SQL injection in the file manager2022-05-24
GHSA
Contao SQL injection in the backend and listing module2022-05-24
CVEList
CVE-2017-16558: Contao 32019-04-25
CVE-2017-16558 — SQL Injection in Contao | cvebase