High severity8.3NVD Advisory· Published Sep 17, 2024· Updated Jun 17, 2026
CVE-2024-45398
CVE-2024-45398
Description
Contao is an Open Source CMS. In affected versions a back end user with access to the file manager can upload malicious files and execute them on the server. Users are advised to update to Contao 4.13.49, 5.3.15 or 5.4.3. Users unable to update are advised to configure their web server so it does not execute PHP files and other scripts in the Contao file upload directory.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
contao/core-bundlePackagist | >= 4.0.0, < 4.13.49 | 4.13.49 |
contao/core-bundlePackagist | >= 5.0.0, < 5.3.15 | 5.3.15 |
contao/core-bundlePackagist | >= 5.4.0, < 5.4.3 | 5.4.3 |
Affected products
3Patches
Vulnerability mechanics
References
7- contao.org/en/security-advisories/remote-command-execution-through-file-uploadsnvdVendor AdvisoryWEB
- github.com/advisories/GHSA-vm6r-j788-hjh5ghsaADVISORY
- github.com/contao/contao/security/advisories/GHSA-vm6r-j788-hjh5nvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2024-45398ghsaADVISORY
- github.com/contao/contao/commit/9445d509f12a7f1b68a4794dcc5e3e459b363ebbghsaWEB
- github.com/contao/contao/commit/a7e39f96ac8fdc281f7caaa96e01deb0e24ac7d3ghsaWEB
- github.com/contao/contao/commit/f3db59ffe5a6c0e1f705b3230ebd5ff16865280eghsaWEB
News mentions
0No linked articles in our index yet.