{"id":"CVE-2019-11512","aliases":["GHSA-vq59-x6mq-4wgw"],"url":"https://o3.security/vulnerability/CVE-2019-11512","summary":"Contao SQL injection in the file manager","details":"David Wind, penetration tester with A1 Digital, has discovered that the SQL injection vulnerability originally published under CVE-2017-16558 can still be exploited in the file manager in Contao 4. ","published":"2019-07-09T21:15:10.897Z","modified":"2026-08-07T15:00:06.289449Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":{"score":0.01462,"percentile":0.7233,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"contao/contao","fixedVersion":"4.4.39"},{"ecosystem":"Packagist","name":"contao/contao","fixedVersion":"4.7.5"},{"ecosystem":"Packagist","name":"contao/core-bundle","fixedVersion":"4.4.39"},{"ecosystem":"Packagist","name":"contao/core-bundle","fixedVersion":"4.7.5"}],"fix":{"url":"https://github.com/contao/contao/commit/87d92f823b08b91a0aeb522284537c8afcdb8aba","label":"contao/contao@87d92f8"},"references":[{"type":"ADVISORY","url":"https://contao.org/en/news/security-vulnerability-cve-2019-11512.html"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-11512"},{"type":"WEB","url":"https://github.com/contao/contao/commit/87d92f823b08b91a0aeb522284537c8afcdb8aba"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/contao/contao/CVE-2019-11512.yaml"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/contao/core-bundle/CVE-2019-11512.yaml"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T15:00:06.289449Z"}}