Cross-Site Request Forgery Vulnerability in Contao by Contao
CVE-2012-1297

Currently unrated

Key Information:

Vendor

Contao

Vendor
CVE Published:
19 March 2012

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2012-1297?

Multiple cross-site request forgery (CSRF) vulnerabilities in the main.php file of Contao (formerly TYPOlight) version 2.11.0 and earlier can allow remote attackers to exploit the system. By performing malicious actions, attackers may hijack administrator authentication to execute delete operations in the user, news, and newsletter modules. This presents significant risks to data integrity and administrator control, highlighting the importance of securing web applications against CSRF threats.

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.