{"id":"CVE-2019-10643","aliases":["GHSA-j99g-qjvx-995g"],"url":"https://o3.security/vulnerability/CVE-2019-10643","summary":"Contao Does Not Expire Tokens Correctly","details":"Security researcher Ali Razzaq has discovered that confirming an opt-in token does not invalidate previous opt-in tokens in Contao 4.7.","published":"2019-04-17T19:29:00.597Z","modified":"2026-08-07T14:49:44.656767Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":{"score":0.01254,"percentile":0.68036,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"contao/contao","fixedVersion":"4.7.3"},{"ecosystem":"Packagist","name":"contao/core-bundle","fixedVersion":"4.7.3"}],"fix":{"url":"https://github.com/contao/contao/commit/70348cc812b110831ad66a4f9857883f75649b88","label":"contao/contao@70348cc"},"references":[{"type":"ADVISORY","url":"https://contao.org/en/news.html"},{"type":"ADVISORY","url":"https://contao.org/en/news/security-vulnerability-cve-2019-10643.html"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-10643"},{"type":"WEB","url":"https://github.com/contao/contao/commit/70348cc812b110831ad66a4f9857883f75649b88"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/contao/contao/CVE-2019-10643.yaml"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/contao/core-bundle/CVE-2019-10643.yaml"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T14:49:44.656767Z"}}