VDB
Sign up
HIGH8.8

GHSA-x5g4-crxq-qxjx

Contao Core directory traversal vulnerability

Quick fix

GHSA-x5g4-crxq-qxjx — contao/contao: upgrade to the fixed version with the command below.

composer require contao/contao:^4.4.1

Details

A logged in back end user can include arbitrary PHP files by manipulating an URL parameter. Since Contao does not allow to upload PHP files in the file manager, the attack is limited to the existing PHP files on the server.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/contao/contao
Introduced in: 4.0.0Fixed in: 4.4.1
Fixcomposer require contao/contao:^4.4.1
Packagist/contao/core-bundle
Introduced in: 4.0.0Fixed in: 4.4.1
Fixcomposer require contao/core-bundle:^4.4.1
Packagist/contao/core
Introduced in: 3.0.0Fixed in: 3.5.28
Fixcomposer require contao/core:^3.5.28

References