Description
Contao is an open source content management system. Prior to version 4.13.40, when a frontend member changes their password in the personal data or the password lost module, the corresponding remember-me tokens are not removed. If someone compromises an account and is able to get a remember-me token, changing the password would not be enough to reclaim control over the account. Version 4.13.40 contains a fix for the issue. As a workaround, disable "Allow auto login" in the login module.
Published: 2024-04-09
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-1288 Contao is an open source content management system. Prior to version 4.13.40, when a frontend member changes their password in the personal data or the password lost module, the corresponding remember-me tokens are not removed. If someone compromises an account and is able to get a remember-me token, changing the password would not be enough to reclaim control over the account. Version 4.13.40 contains a fix for the issue. As a workaround, disable "Allow auto login" in the login module.
Github GHSA Github GHSA GHSA-r4r6-j2j3-7pp5 Contao: Remember-me tokens will not be cleared after a password change
History

Thu, 09 Jan 2025 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Contao
Contao contao
CPEs cpe:2.3:a:contao:contao:*:*:*:*:*:*:*:*
Vendors & Products Contao
Contao contao

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-08-02T01:32:07.058Z

Reserved: 2024-03-26T12:52:00.935Z

Link: CVE-2024-30262

cve-icon Vulnrichment

Updated: 2024-08-02T01:32:07.058Z

cve-icon NVD

Status : Analyzed

Published: 2024-04-09T17:16:02.850

Modified: 2025-01-09T17:51:27.337

Link: CVE-2024-30262

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses