title: A logged in back end user can include arbitrary existing PHP files by manipulating an URL parameter
link: https://contao.org/en/news/contao-3_5_28.html
cve: CVE-2017-10993
branches:
3.x:
time: 2017-07-12 07:10:24
versions: ['>=3.0.0', '<3.5.28']
reference: composer://contao/core