It is possible for untrusted users to load arbitrary PHP files via insert tags.
Installations are only affected if there are untrusted back end users.
Update to Contao 4.4.56, 4.9.18 or 4.11.7.
Disable the login for untrusted back end users.
https://contao.org/en/security-advisories/php-file-inclusion-via-insert-tags
If you have any questions or comments about this advisory, open an issue in contao/contao.
{ "nvd_published_at": "2021-08-11T23:15:00Z", "cwe_ids": [ "CWE-94" ], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2021-08-23T16:51:34Z" }