Contao is an open source content management system. Prior to versions 4.9.40, 4.13.21, and 5.1.4, logged in users can list arbitrary system files in the file manager by manipulating the Ajax request. However, it is not possible to read the contents of these files. Users should update to Contao 4.9.40, 4.13.21 or 5.1.4 to receive a patch. There are no known workarounds.
Metrics
Affected Vendors & Products
References
History
Mon, 03 Feb 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2023-04-25T17:00:29.537Z
Updated: 2025-02-03T19:37:13.854Z
Reserved: 2023-04-03T13:37:18.454Z
Link: CVE-2023-29200
Updated: 2024-08-02T14:00:15.870Z
Status : Undergoing Analysis
Published: 2023-04-25T18:15:09.510
Modified: 2025-01-02T17:22:06.893
Link: CVE-2023-29200
No data.