PT-2024-23305 · Contao · Contao

·

CVE-2024-30262

·

Published

2024-04-09

·

Updated

2025-01-09

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Contao versions prior to 4.13.40
Description Contao is an open source content management system. When a frontend member changes their password in the personal data or the password lost module, the corresponding remember-me tokens are not removed. If someone compromises an account and is able to get a remember-me token, changing the password would not be enough to reclaim control over the account.
Recommendations Update to Contao version 4.13.40 to resolve the issue. As a temporary workaround, disable "Allow auto login" in the login module.

Exploit

Fix

Session Fixation

Insufficient Session Expiration

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-30262
GHSA-R4R6-J2J3-7PP5

Affected Products

Contao