Impact
Contao’s ImagesController combines a user‑supplied {path} parameter with the configured image directory using Path::join() but fails to confirm that the resulting canonical path still resides within that directory. As a result, an attacker can supply encoded parent‑directory segments to read any file whose name ends with an extension allowed by contao.image.valid_extensions. The returned file is provided via BinaryFileResponse, enabling the disclosure of project‑level files to unauthenticated users. The route can also be used to determine whether arbitrary paths exist, and when debug responses are enabled, absolute filesystem paths may be exposed. Overall, the vulnerability enables information disclosure rather than code execution.
Affected Systems
All installations of contao:contao from version 5.0.0 up to the release of 5.3.50 and up to 5.7.12 are vulnerable. Versions 5.3.50, 5.7.12 and newer contain the fix and are therefore not affected.
Risk and Exploitability
The CVSS score of 5.3 indicates medium severity, and the EPSS score is not available, suggesting that no current exploitation data is reported. The vulnerability is listed as not being in the CISA KEV catalog. An attacker can trigger it by sending an unauthenticated HTTP request to the images controller, incorporating parent‑directory encodings to traverse directories, and supplying a valid file extension. The attack is straightforward for an attacker with network access to the web server; no prior authentication, privilege escalation, or code execution is required. The primary risk is the accidental or intentional disclosure of configuration, application source, or other sensitive files included in the Contao project directory.
OpenCVE Enrichment