Contao is an open source content management system. Prior to versions 4.9.40, 4.13.21, and 5.1.4, logged in users can list arbitrary system files in the file manager by manipulating the Ajax request. However, it is not possible to read the contents of these files. Users should update to Contao 4.9.40, 4.13.21 or 5.1.4 to receive a patch. There are no known workarounds.
History

Mon, 03 Feb 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-02-03T19:37:13.854Z

Reserved: 2023-04-03T13:37:18.454Z

Link: CVE-2023-29200

cve-icon Vulnrichment

Updated: 2024-08-02T14:00:15.870Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2023-04-25T18:15:09.510

Modified: 2025-01-02T17:22:06.893

Link: CVE-2023-29200

cve-icon Redhat

No data.