by Leo Feyer

Bypassing the request token check

Date: 2019-04-09
CVE ID: CVE-2019-10642

Description

Security researcher Ali Razzaq has discovered that the request token check can be bypassed in Contao 4.7

Affected versions

Contao 4.7 up to 4.7.2

Suggested solution

Update to Contao 4.7.3.