Contao 4.0 through 4.8.5 allows PHP local file inclusion. A back end user with access to the form generator can upload arbitrary files and execute them on the server.
Advisories
Source ID Title
EUVD EUVD EUVD-2019-0804 Contao 4.0 through 4.8.5 allows PHP local file inclusion. A back end user with access to the form generator can upload arbitrary files and execute them on the server.
Github GHSA Github GHSA GHSA-wjx8-cgrm-hh8p Unrestricted file uploads in Contao
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T02:25:12.676Z

Reserved: 2019-12-12T00:00:00

Link: CVE-2019-19745

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-12-17T15:15:25.957

Modified: 2024-11-21T04:35:18.203

Link: CVE-2019-19745

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses