CVE-2024-45604

Contao is an Open Source CMS. In affected versions authenticated users in the back end can list files outside the document root in the file selector widget. Users are advised to update to Contao 4.13.49. There are no known workarounds for this vulnerability.
Configurations

Configuration 1 (hide)

cpe:2.3:a:contao:contao:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-09-17 20:15

Updated : 2024-09-25 19:22


NVD link : CVE-2024-45604

Mitre link : CVE-2024-45604

CVE.ORG link : CVE-2024-45604


JSON object : View

Products Affected

contao

  • contao
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')