CVE-2024-45398
HIGH8.3EPSS 0.21%Contao affected by remote command execution through file upload
發布日:2024/9/17修改日:2024/9/17
描述
### Impact Back end users with access to the file manager can upload malicious files and execute them on the server. ### Patches Update to Contao 4.13.49, 5.3.15 or 5.4.3. ### Workarounds Configure your web server so it does not execute PHP files and other scripts in the Contao file upload directory. ### References https://contao.org/en/security-advisories/remote-command-execution-through-file-uploads ### For more information If you have any questions or comments about this advisory, open an issue in [contao/contao](https://github.com/contao/contao/issues/new/choose). ### Credits Thanks to Jakob Steeg from usd AG for reporting this vulnerability.
受影響套件(1)
- Packagist/contao/core-bundle>= 4.0.0, < 4.13.49
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N |
| osv | CVSS 3.1 | HIGH8.3 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L |
參考連結(7)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2024-45398
- PATCHhttps://github.com/contao/contao
- WEBhttps://contao.org/en/security-advisories/remote-command-execution-through-file-uploads
- WEBhttps://github.com/contao/contao/commit/9445d509f12a7f1b68a4794dcc5e3e459b363ebb
- WEBhttps://github.com/contao/contao/commit/a7e39f96ac8fdc281f7caaa96e01deb0e24ac7d3
- WEBhttps://github.com/contao/contao/commit/f3db59ffe5a6c0e1f705b3230ebd5ff16865280e
- WEBhttps://github.com/contao/contao/security/advisories/GHSA-vm6r-j788-hjh5