{"id":"CVE-2024-45398","aliases":["GHSA-vm6r-j788-hjh5"],"url":"https://o3.security/vulnerability/CVE-2024-45398","summary":"Remote command execution through file upload in contao/core-bundle","details":"### Impact\n\nBack end users with access to the file manager can upload malicious files and execute them on the server.\n\n### Patches\n\nUpdate to Contao 4.13.49, 5.3.15 or 5.4.3.\n\n### Workarounds\n\nConfigure your web server so it does not execute PHP files and other scripts in the Contao file upload directory.\n\n### References\n\nhttps://contao.org/en/security-advisories/remote-command-execution-through-file-uploads\n\n### For more information\n\nIf you have any questions or comments about this advisory, open an issue in [contao/contao](https://github.com/contao/contao/issues/new/choose).\n\n### Credits\n\nThanks to Jakob Steeg from usd AG for reporting this vulnerability.","published":"2024-09-17T19:56:00.791Z","modified":"2026-08-12T03:51:47.902137659Z","cvss":{"score":8.3,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"contao/core-bundle","fixedVersion":"4.13.49"},{"ecosystem":"Packagist","name":"contao/core-bundle","fixedVersion":"5.3.15"},{"ecosystem":"Packagist","name":"contao/core-bundle","fixedVersion":"5.4.3"}],"fix":{"url":"https://github.com/contao/contao/commit/9445d509f12a7f1b68a4794dcc5e3e459b363ebb","label":"contao/contao@9445d50"},"references":[{"type":"ADVISORY","url":"https://contao.org/en/security-advisories/remote-command-execution-through-file-uploads"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/45xxx/CVE-2024-45398.json"},{"type":"ADVISORY","url":"https://github.com/contao/contao/security/advisories/GHSA-vm6r-j788-hjh5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-45398"},{"type":"WEB","url":"https://github.com/contao/contao/commit/9445d509f12a7f1b68a4794dcc5e3e459b363ebb"},{"type":"WEB","url":"https://github.com/contao/contao/commit/a7e39f96ac8fdc281f7caaa96e01deb0e24ac7d3"},{"type":"WEB","url":"https://github.com/contao/contao/commit/f3db59ffe5a6c0e1f705b3230ebd5ff16865280e"},{"type":"PACKAGE","url":"https://github.com/contao/contao"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:47.902137659Z"}}