contao/core-bundle Security Advisories for 5.7.11 (9)
-
Cross-site scripting in the frontend search results (see GHSA-h57j-5f5m-789v)
Affected version: >=4.9.0,<5.3.50|>=5.4.0,<5.7.12
Reported by:
FriendsOfPHP/security-advisories -
Unrestricted activation email resending (see GHSA-mfxh-vp55-7gc6)
Affected version: >=4.1.0,<5.3.50|>=5.4.0,<5.7.12
Reported by:
FriendsOfPHP/security-advisories -
Non-admin users can self-grant permissions that implicitly make them administrators (see GHSA-r9qp-pqx5-8369)
Affected version: >=5.0.0,<5.3.50|>=5.4.0,<5.7.12
Reported by:
FriendsOfPHP/security-advisories -
Cross-site request forgery in custom backend actions (see GHSA-9ff2-p842-45wq)
Affected version: >=4.0.0,<5.3.50|>=5.4.0,<5.7.12
Reported by:
FriendsOfPHP/security-advisories -
Exposure of sensitive information through a stale search index (see GHSA-x2rp-9qf7-2fmq)
Affected version: >=4.0.0,<5.3.50|>=5.4.0,<5.7.12
Reported by:
FriendsOfPHP/security-advisories -
Path traversal in the images controller (see GHSA-mrvp-7wmx-5m4h)
Affected version: >=5.0.0,<5.3.50|>=5.4.0,<5.7.12
Reported by:
FriendsOfPHP/security-advisories -
Improper access control in the CSV import wizard (see GHSA-23w9-4pg3-xwm3)
Affected version: >=5.0.0,<5.3.50|>=5.4.0,<5.7.12
Reported by:
FriendsOfPHP/security-advisories -
Improper access control in the preview links module (see GHSA-q6wp-fr43-gm9v)
Affected version: >=5.7.1,<5.7.12
Reported by:
FriendsOfPHP/security-advisories -
Improper access control in the table access voter (see GHSA-5974-gfqc-wrcm)
Affected version: >=5.7.0,<5.7.12
Reported by:
FriendsOfPHP/security-advisories