Contao is an open source content management system. Prior to versions 4.9.40, 4.13.21, and 5.1.4, logged in users can list arbitrary system files in the file manager by manipulating the Ajax request. However, it is not possible to read the contents of these files. Users should update to Contao 4.9.40, 4.13.21 or 5.1.4 to receive a patch. There are no known workarounds.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: GitHub_M

Published: 2023-04-25T17:00:29.537Z

Updated: 2023-04-25T17:00:29.537Z

Reserved: 2023-04-03T13:37:18.454Z


Link: CVE-2023-29200

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-04-25T18:15:09.510

Modified: 2023-05-04T19:35:45.310


Link: CVE-2023-29200

JSON object: View

cve-icon Redhat Information

No data.

CWE