CVE-2024-30262

CVSS V2 None CVSS V3 None
Description
Contao is an open source content management system. Prior to version 4.13.40, when a frontend member changes their password in the personal data or the password lost module, the corresponding remember-me tokens are not removed. If someone compromises an account and is able to get a remember-me token, changing the password would not be enough to reclaim control over the account. Version 4.13.40 contains a fix for the issue. As a workaround, disable "Allow auto login" in the login module.
Overview
  • CVE ID
  • CVE-2024-30262
  • Assigner
  • GitHub_M
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-04-09T16:45:57.132Z
  • Last Modified Date
  • 2024-06-04T17:39:15.815Z
History
Created Old Value New Value Data Type Notes
2024-06-26 11:57:52 Added to TrackCVE