Arbitrary file upload in Contao - CVE-2024-45398
Published: September 17, 2024 / Updated: May 5, 2026
Contao
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary code on the server.
The vulnerability exists due to unrestricted upload of files with dangerous types in the file manager when uploading files. A remote user can upload a malicious file to execute arbitrary code on the server.
Exploitation requires access to the back end file manager.