PT-2019-15943 · Contao · Contao
Leo Feyer
·
Publicado
2019-12-17
·
Atualizado
2019-12-18
·
CVE-2019-19745
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Contao versions 4.0 through 4.8.5
Description
The issue allows a back end user with access to the form generator to upload arbitrary files and execute them on the server, enabling PHP local file inclusion. This can be exploited by a user with access to the form generator.
Recommendations
Update to Contao 4.4.46 or 4.8.6.
As a temporary workaround, configure your web server so it does not execute PHP files and other scripts in the Contao file upload directory.
Exploit
Correção
Unrestricted File Upload
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Contao