Contao is an open source content management system. Prior to versions 4.9.40, 4.13.21, and 5.1.4, logged in users can list arbitrary system files in the file manager by manipulating the Ajax request. However, it is not possible to read the contents of these files. Users should update to Contao 4.9.40, 4.13.21 or 5.1.4 to receive a patch. There are no known workarounds.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-1294 Contao is an open source content management system. Prior to versions 4.9.40, 4.13.21, and 5.1.4, logged in users can list arbitrary system files in the file manager by manipulating the Ajax request. However, it is not possible to read the contents of these files. Users should update to Contao 4.9.40, 4.13.21 or 5.1.4 to receive a patch. There are no known workarounds.
Github GHSA Github GHSA GHSA-fp7q-xhhw-6rj3 Path traversal vulnerability in the file manager
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 03 Feb 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-02-03T19:37:13.854Z

Reserved: 2023-04-03T13:37:18.454Z

Link: CVE-2023-29200

cve-icon Vulnrichment

Updated: 2024-08-02T14:00:15.870Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2023-04-25T18:15:09.510

Modified: 2025-01-02T17:22:06.893

Link: CVE-2023-29200

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.