CVE-2012-1297
19.03.2012, 18:55
Multiple cross-site request forgery (CSRF) vulnerabilities in main.php in Contao (formerly TYPOlight) 2.11.0 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) delete users via a delete action in the user module, (2) delete news via a delete action in the news module, or (3) delete newsletters via a delete action in the newsletters module.
Vendor | Product | Version |
---|---|---|
contao | contao_cms | 𝑥 ≤ 2.11.0 |
contao | contao_cms | 2.0 |
contao | contao_cms | 2.0:beta-rc2 |
contao | contao_cms | 2.0:beta-rc3 |
contao | contao_cms | 2.1.0 |
contao | contao_cms | 2.1.1 |
contao | contao_cms | 2.1.2 |
contao | contao_cms | 2.1.3 |
contao | contao_cms | 2.1.4 |
contao | contao_cms | 2.1.5 |
contao | contao_cms | 2.1.6 |
contao | contao_cms | 2.1.7 |
contao | contao_cms | 2.1.8 |
contao | contao_cms | 2.1.9 |
contao | contao_cms | 2.1.10 |
contao | contao_cms | 2.1.11 |
contao | contao_cms | 2.1.12 |
contao | contao_cms | 2.1.13 |
contao | contao_cms | 2.1.14 |
contao | contao_cms | 2.1.15 |
contao | contao_cms | 2.1.16 |
contao | contao_cms | 2.1.17 |
contao | contao_cms | 2.1.18 |
contao | contao_cms | 2.1.19 |
contao | contao_cms | 2.1.20 |
contao | contao_cms | 2.2.0 |
contao | contao_cms | 2.2.1 |
contao | contao_cms | 2.2.2 |
contao | contao_cms | 2.2.3 |
contao | contao_cms | 2.2.4 |
contao | contao_cms | 2.2.5 |
contao | contao_cms | 2.2.6 |
contao | contao_cms | 2.2.7 |
contao | contao_cms | 2.2.8 |
contao | contao_cms | 2.2.9 |
contao | contao_cms | 2.2.10 |
contao | contao_cms | 2.2.11 |
contao | contao_cms | 2.2.12 |
contao | contao_cms | 2.3.0 |
contao | contao_cms | 2.3.1 |
contao | contao_cms | 2.3.2 |
contao | contao_cms | 2.3.3 |
contao | contao_cms | 2.3.4 |
contao | contao_cms | 2.4.0 |
contao | contao_cms | 2.4.0:beta |
contao | contao_cms | 2.4.1 |
contao | contao_cms | 2.4.2 |
contao | contao_cms | 2.4.3 |
contao | contao_cms | 2.4.4 |
contao | contao_cms | 2.4.5 |
contao | contao_cms | 2.4.6 |
contao | contao_cms | 2.4.7 |
contao | contao_cms | 2.5.0 |
contao | contao_cms | 2.5.0:beta |
contao | contao_cms | 2.5.0:beta-rc2 |
contao | contao_cms | 2.5.1 |
contao | contao_cms | 2.5.2 |
contao | contao_cms | 2.5.3 |
contao | contao_cms | 2.5.4 |
contao | contao_cms | 2.5.5 |
contao | contao_cms | 2.5.6 |
contao | contao_cms | 2.5.7 |
contao | contao_cms | 2.5.8 |
contao | contao_cms | 2.5.9 |
contao | contao_cms | 2.6.0 |
contao | contao_cms | 2.6.0:beta |
contao | contao_cms | 2.6.0:beta2 |
contao | contao_cms | 2.6.1 |
contao | contao_cms | 2.6.2 |
contao | contao_cms | 2.6.3 |
contao | contao_cms | 2.6.4 |
contao | contao_cms | 2.6.5 |
contao | contao_cms | 2.6.6 |
contao | contao_cms | 2.6.7 |
contao | contao_cms | 2.6.8 |
contao | contao_cms | 2.7.0 |
contao | contao_cms | 2.7.0:rc1 |
contao | contao_cms | 2.7.0:rc2 |
contao | contao_cms | 2.7.1 |
contao | contao_cms | 2.7.2 |
contao | contao_cms | 2.7.3 |
contao | contao_cms | 2.7.4 |
contao | contao_cms | 2.7.5 |
contao | contao_cms | 2.7.6 |
contao | contao_cms | 2.7.7 |
contao | contao_cms | 2.8.0 |
contao | contao_cms | 2.8.0:rc1 |
contao | contao_cms | 2.8.0:rc2 |
contao | contao_cms | 2.8.1 |
contao | contao_cms | 2.8.2 |
contao | contao_cms | 2.8.3 |
contao | contao_cms | 2.8.4 |
contao | contao_cms | 2.9.0 |
contao | contao_cms | 2.9.0:beta1 |
contao | contao_cms | 2.9.0:rc1 |
contao | contao_cms | 2.9.1 |
contao | contao_cms | 2.9.2 |
contao | contao_cms | 2.9.3 |
contao | contao_cms | 2.9.4 |
contao | contao_cms | 2.9.5 |
contao | contao_cms | 2.10.:beta |
contao | contao_cms | 2.10.0 |
contao | contao_cms | 2.10.0:rc1 |
contao | contao_cms | 2.10.1 |
contao | contao_cms | 2.10.2 |
contao | contao_cms | 2.10.3 |
contao | contao_cms | 2.10.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References