HIGH8.8
GHSA-x5g4-crxq-qxjx
Contao Core directory traversal vulnerability
Quick fix
GHSA-x5g4-crxq-qxjx — contao/contao: upgrade to the fixed version with the command below.
composer require contao/contao:^4.4.1Details
A logged in back end user can include arbitrary PHP files by manipulating an URL parameter. Since Contao does not allow to upload PHP files in the file manager, the attack is limited to the existing PHP files on the server.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/contao/core-bundle
Introduced in:
4.0.0Fixed in: 4.4.1Fix
composer require contao/core-bundle:^4.4.1References
- https://nvd.nist.gov/vuln/detail/CVE-2017-10993[ADVISORY]
- https://contao.org/en/news/contao-3_5_28.html[WEB]
- https://contao.org/en/news/contao-4_4_1.html[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/contao/contao/CVE-2017-10993.yaml[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/contao/core-bundle/CVE-2017-10993.yaml[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/contao/core/CVE-2017-10993.yaml[WEB]