Contao is an open source content management system. Prior to versions 4.9.40, 4.13.21, and 5.1.4, logged in users can list arbitrary system files in the file manager by manipulating the Ajax request. However, it is not possible to read the contents of these files. Users should update to Contao 4.9.40, 4.13.21 or 5.1.4 to receive a patch. There are no known workarounds.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-1294 | Contao is an open source content management system. Prior to versions 4.9.40, 4.13.21, and 5.1.4, logged in users can list arbitrary system files in the file manager by manipulating the Ajax request. However, it is not possible to read the contents of these files. Users should update to Contao 4.9.40, 4.13.21 or 5.1.4 to receive a patch. There are no known workarounds. |
Github GHSA |
GHSA-fp7q-xhhw-6rj3 | Path traversal vulnerability in the file manager |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 03 Feb 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-02-03T19:37:13.854Z
Reserved: 2023-04-03T13:37:18.454Z
Link: CVE-2023-29200
Updated: 2024-08-02T14:00:15.870Z
Status : Undergoing Analysis
Published: 2023-04-25T18:15:09.510
Modified: 2025-01-02T17:22:06.893
Link: CVE-2023-29200
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA