← Back

CVE-2023-29200

nvd nist
Published: Apr 25, 2023Modified: Jan 2, 2025

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

Contao is an open source content management system. Prior to versions 4.9.40, 4.13.21, and 5.1.4, logged in users can list arbitrary system files in the file manager by manipulating the Ajax request. However, it is not possible to read the contents of these files. Users should update to Contao 4.9.40, 4.13.21 or 5.1.4 to receive a patch. There are no known workarounds.

Affected (3)

Products: Contao: Contao
1 product
Contao
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Contao
From 2.0 to 4.9.40
From 4.10.0 to 4.13.21
From 5.0.0 to 5.1.4

References (6)

Source: security-advisories@github.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.