Lack of data validation - Path Traversal In contao/core
Description
Contao Core directory traversal vulnerability Directory traversal vulnerability in Contao before 3.2.19, and 3.4.x before 3.4.4 allows remote authenticated backend users to view files outside their file mounts or the document root via unspecified vectors.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
packagist | 3.4.4, 3.2.19 |
Aliases
1. 2. 3. 4.
References
1. 2. 3. 4. 5.