Path traversal vulnerability in the file manager
Package
Affected versions
>= 4.9.0, < 4.9.40
>= 4.13.0, < 4.13.21
>= 5.1.0, < 5.1.4
Patched versions
4.9.40
4.13.21
5.1.4
Description
Published by the National Vulnerability Database
Apr 25, 2023
Published to the GitHub Advisory Database
Apr 26, 2023
Reviewed
Apr 26, 2023
Last updated
Nov 11, 2023
Impact
Authenticated users in the back end can list files outside the document root in the file manager.
Patches
Update to Contao 4.9.40, 4.13.21 or 5.1.4.
Workarounds
None.
References
https://contao.org/en/security-advisories/directory-traversal-in-the-file-manager
For more information
If you have any questions or comments about this advisory, open an issue in contao/contao.
References