Contao is an open source content management system. Prior to versions 4.9.40, 4.13.21, and 5.1.4, logged in users can list arbitrary system files in the file manager by manipulating the Ajax request. However, it is not possible to read the contents of these files. Users should update to Contao 4.9.40, 4.13.21 or 5.1.4 to receive a patch. There are no known workarounds.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2023-04-25T17:00:29.537Z

Updated: 2024-08-02T14:00:15.870Z

Reserved: 2023-04-03T13:37:18.454Z

Link: CVE-2023-29200

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2023-04-25T18:15:09.510

Modified: 2023-05-04T19:35:45.310

Link: CVE-2023-29200

cve-icon Redhat

No data.