← Back

CVE-2012-1297

nvd nist
Published: Mar 19, 2012Modified: Apr 29, 2026

JSON object

Loading...
6.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:P
Exploitability: 8.6 / Impact: 6.4
Source: NVD

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in main.php in Contao (formerly TYPOlight) 2.11.0 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) delete users via a delete action in the user module, (2) delete news via a delete action in the news module, or (3) delete newsletters via a delete action in the newsletters module.

Affected (107)

Products: Contao: Contao Cms
1 product
Contao Cms
Configuration A
107 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Contao
Up to 2.11.0
Version 2.0
Version 2.0 beta-rc2
Version 2.0 beta-rc3
Version 2.1.0
Version 2.1.10
Version 2.1.11
Version 2.1.12
Version 2.1.13
Version 2.1.14
Version 2.1.15
Version 2.1.16
Version 2.1.17
Version 2.1.18
Version 2.1.19
Version 2.1.1
Version 2.1.20
Version 2.1.2
Version 2.1.3
Version 2.1.4
Version 2.1.5
Version 2.1.6
Version 2.1.7
Version 2.1.8
Version 2.1.9
Version 2.10.0
Version 2.10.0 rc1
Version 2.10.1
Version 2.10.2
Version 2.10.3
Version 2.10.4
Version 2.10. beta
Version 2.2.0
Version 2.2.10
Version 2.2.11
Version 2.2.12
Version 2.2.1
Version 2.2.2
Version 2.2.3
Version 2.2.4
Version 2.2.5
Version 2.2.6
Version 2.2.7
Version 2.2.8
Version 2.2.9
Version 2.3.0
Version 2.3.1
Version 2.3.2
Version 2.3.3
Version 2.3.4
Version 2.4.0
Version 2.4.0 beta
Version 2.4.1
Version 2.4.2
Version 2.4.3
Version 2.4.4
Version 2.4.5
Version 2.4.6
Version 2.4.7
Version 2.5.0
Version 2.5.0 beta-rc2
Version 2.5.0 beta
Version 2.5.1
Version 2.5.2
Version 2.5.3
Version 2.5.4
Version 2.5.5
Version 2.5.6
Version 2.5.7
Version 2.5.8
Version 2.5.9
Version 2.6.0
Version 2.6.0 beta2
Version 2.6.0 beta
Version 2.6.1
Version 2.6.2
Version 2.6.3
Version 2.6.4
Version 2.6.5
Version 2.6.6
Version 2.6.7
Version 2.6.8
Version 2.7.0
Version 2.7.0 rc1
Version 2.7.0 rc2
Version 2.7.1
Version 2.7.2
Version 2.7.3
Version 2.7.4
Version 2.7.5
Version 2.7.6
Version 2.7.7
Version 2.8.0
Version 2.8.0 rc1
Version 2.8.0 rc2
Version 2.8.1
Version 2.8.2
Version 2.8.3
Version 2.8.4
Version 2.9.0
Version 2.9.0 beta1
Version 2.9.0 rc1
Version 2.9.1
Version 2.9.2
Version 2.9.3
Version 2.9.4
Version 2.9.5
Running on/withPlatform Versions
Contao
Contao Cms
Version 2.0 beta-rc1

Timeline

No history available yet.