Description
Contao is an open source content management system. Prior to version 4.13.40, when a frontend member changes their password in the personal data or the password lost module, the corresponding remember-me tokens are not removed. If someone compromises an account and is able to get a remember-me token, changing the password would not be enough to reclaim control over the account. Version 4.13.40 contains a fix for the issue. As a workaround, disable "Allow auto login" in the login module.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-1288 | Contao is an open source content management system. Prior to version 4.13.40, when a frontend member changes their password in the personal data or the password lost module, the corresponding remember-me tokens are not removed. If someone compromises an account and is able to get a remember-me token, changing the password would not be enough to reclaim control over the account. Version 4.13.40 contains a fix for the issue. As a workaround, disable "Allow auto login" in the login module. |
Github GHSA |
GHSA-r4r6-j2j3-7pp5 | Contao: Remember-me tokens will not be cleared after a password change |
References
History
Thu, 09 Jan 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Contao
Contao contao |
|
| CPEs | cpe:2.3:a:contao:contao:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Contao
Contao contao |
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-02T01:32:07.058Z
Reserved: 2024-03-26T12:52:00.935Z
Link: CVE-2024-30262
Updated: 2024-08-02T01:32:07.058Z
Status : Analyzed
Published: 2024-04-09T17:16:02.850
Modified: 2025-01-09T17:51:27.337
Link: CVE-2024-30262
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA