MEDIUM
Directory traversal in the file selector widget in contao/core-bundle
Published Sep 17, 2024
5.3
MEDIUMCVSS 4.0
EPSS 0.43%
Description
Contao is an Open Source CMS. In affected versions authenticated users in the back end can list files outside the document root in the file selector widget. Users are advised to update to Contao 4.13.49. There are no known workarounds for this vulnerability.
Affected products
-
Affected
- < 4.13.49
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://contao.org/en/security-advisories/directory-traversal-in-the-fileselector-widget x_refsource_MISCVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-2711 Advisory
- https://github.com/advisories/GHSA-4p75-5p53-65m9 Advisory
- https://github.com/contao/contao/commit/63409c6bdfd95197d9906e229d765b630d45742e
- https://github.com/contao/contao/security/advisories/GHSA-4p75-5p53-65m9 x_refsource_CONFIRMThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-45604
| Link | Providers | Tags |
|---|---|---|
| https://contao.org/en/security-advisories/directory-traversal-in-the-fileselector-widget | x_refsource_MISCVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-2711 | Advisory | |
| https://github.com/advisories/GHSA-4p75-5p53-65m9 | Advisory | |
| https://github.com/contao/contao/commit/63409c6bdfd95197d9906e229d765b630d45742e | ||
| https://github.com/contao/contao/security/advisories/GHSA-4p75-5p53-65m9 | x_refsource_CONFIRMThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2024-45604 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Sep 17, 2024
Updated Sep 18, 2024
Reserved Sep 2, 2024
Link CVE-2024-45604
CISA Vulnrichment
Updated Sep 18, 2024
Red Hat
No data
GitHub
Link GHSA-4P75-5P53-65M9