← Back

CVE-2024-45604

nvd nist
Published: Sep 17, 2024Modified: Sep 25, 2024

JSON object

Loading...
4.3
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Exploitability: 2.8 / Impact: 1.4
Source: NVD

Description

Contao is an Open Source CMS. In affected versions authenticated users in the back end can list files outside the document root in the file selector widget. Users are advised to update to Contao 4.13.49. There are no known workarounds for this vulnerability.

Affected (1)

Products: Contao: Contao
1 product
Contao
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 4.13.49

References (2)

Source: security-advisories@github.com
Third Party Advisory

Timeline

No history available yet.