CVE-2017-16558

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
25/04/2019
Last modified:
26/04/2019

Description

Contao 3.0.0 to 3.5.30 and 4.0.0 to 4.4.7 contains an SQL injection vulnerability in the back end as well as in the listing module.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:contao:contao_cms:*:*:*:*:*:*:*:* 3.0.0 (including) 3.5.30 (including)
cpe:2.3:a:contao:contao_cms:*:*:*:*:*:*:*:* 4.0.0 (including) 4.4.7 (including)