title: A logged in back end user can include arbitrary existing PHP files by manipulating an URL parameter
link: https://contao.org/en/news/contao-4_4_1.html
cve: CVE-2017-10993
branches:
4.x:
time: 2017-07-12 09:09:38
versions: ['>=4.0.0', '<4.4.1']
reference: composer://contao/core-bundle