Cross-Site Request Forgery Vulnerability in Contao by Contao
CVE-2012-1297
Currently unrated
Key Information:
- Vendor
Contao
- Status
- Vendor
- CVE Published:
- 19 March 2012
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2012-1297?
Multiple cross-site request forgery (CSRF) vulnerabilities in the main.php file of Contao (formerly TYPOlight) version 2.11.0 and earlier can allow remote attackers to exploit the system. By performing malicious actions, attackers may hijack administrator authentication to execute delete operations in the user, news, and newsletter modules. This presents significant risks to data integrity and administrator control, highlighting the importance of securing web applications against CSRF threats.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
