Contao CMS through 3.2.4 has PHP Object Injection Vulnerabilities
Contao CMS
Exploit
CVE-2014-1860
NVD
Refer to CVE-2014-1860 NVD advisory