Contao is an Open Source CMS. In affected versions authenticated users in the back end can list files outside the document root in the file selector widget. Users are advised to update to Contao 4.13.49. There are no known workarounds for this vulnerability.
History

Wed, 25 Sep 2024 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Contao
Contao contao
CPEs cpe:2.3:a:contao:contao:*:*:*:*:*:*:*:*
Vendors & Products Contao
Contao contao

Wed, 18 Sep 2024 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 17 Sep 2024 20:00:00 +0000

Type Values Removed Values Added
Description Contao is an Open Source CMS. In affected versions authenticated users in the back end can list files outside the document root in the file selector widget. Users are advised to update to Contao 4.13.49. There are no known workarounds for this vulnerability.
Title Directory traversal in the file selector widget in contao/core-bundle
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-09-17T19:56:02.588Z

Updated: 2024-09-18T13:09:48.444Z

Reserved: 2024-09-02T16:00:02.424Z

Link: CVE-2024-45604

cve-icon Vulnrichment

Updated: 2024-09-18T13:09:42.988Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-17T20:15:04.893

Modified: 2024-09-25T19:22:09.533

Link: CVE-2024-45604

cve-icon Redhat

No data.