PT-2019-15943 · Contao · Contao

Leo Feyer

·

Publicado

2019-12-17

·

Atualizado

2019-12-18

·

CVE-2019-19745

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Contao versions 4.0 through 4.8.5
Description The issue allows a back end user with access to the form generator to upload arbitrary files and execute them on the server, enabling PHP local file inclusion. This can be exploited by a user with access to the form generator.
Recommendations Update to Contao 4.4.46 or 4.8.6. As a temporary workaround, configure your web server so it does not execute PHP files and other scripts in the Contao file upload directory.

Exploit

Correção

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-19745
GHSA-WJX8-CGRM-HH8P

Produtos afetados

Contao