SQL Injection Vulnerability in Contao from Contao Open Source
CVE-2017-16558
9.8CRITICAL
What is CVE-2017-16558?
An SQL injection vulnerability exists in Contao versions 3.0.0 through 3.5.30 and 4.0.0 through 4.4.7, allowing attackers to execute arbitrary SQL queries. This vulnerability arises in both the backend and the listing module, potentially enabling unauthorized access to sensitive database information. Users are strongly advised to upgrade to a secure version to mitigate associated risks.
