CVE-2024-45398 - CVE House
Back to Database
Status published High CVE-2024-45398

Remote command execution through file upload in contao/core-bundle

Vulnerability Description

Contao is an Open Source CMS. In affected versions a back end user with access to the file manager can upload malicious files and execute them on the server. Users are advised to update to Contao 4.13.49, 5.3.15 or 5.4.3. Users unable to update are advised to configure their web server so it does not execute PHP files and other scripts in the Contao file upload directory.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-45398

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

contao
Vulnerable Versions:
>=4.0.0, < 4.13.49, >= 5.0.0, < 5.3.15, >= 5.4.0, < 5.4.3

Timeline

Official Publish: September 17th, 2024
Last Modified: September 18th, 2024
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L

Weaknesses (CWE)