8.8

CVE-2024-45398

Remote command execution through file upload in contao/core-bundle

Contao is an Open Source CMS. In affected versions a back end user with access to the file manager can upload malicious files and execute them on the server. Users are advised to update to Contao 4.13.49, 5.3.15 or 5.4.3. Users unable to update are advised to configure their web server so it does not execute PHP files and other scripts in the Contao file upload directory.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ContaoContao Version >= 4.0.0 < 4.13.49
ContaoContao Version >= 5.0.0 < 5.3.15
ContaoContao Version >= 5.4.0 < 5.4.3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.53% 0.407
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
security-advisories@github.com 8.3 2.8 5.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
CWE-434 Unrestricted Upload of File with Dangerous Type

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

https://contao.org/en/security-advisories/remote-command-execution-through-file-uploads
Vendor Advisory
https://github.com/contao/contao/security/advisories/GHSA-vm6r-j788-hjh5
Third Party Advisory