Vulnerability Description
Contao before 3.5.28 and 4.x before 4.4.1 allows remote attackers to include and execute arbitrary local PHP files via a crafted parameter in a URL, aka Directory Traversal.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Contao | Contao Cms | <= 3.5.27 |
Related Weaknesses (CWE)
References
- https://contao.org/en/news/contao-3_5_28.htmlVendor Advisory
- https://contao.org/en/news/contao-3_5_28.htmlVendor Advisory
FAQ
What is CVE-2017-10993?
CVE-2017-10993 is a vulnerability with a CVSS score of 8.8 (HIGH). Contao before 3.5.28 and 4.x before 4.4.1 allows remote attackers to include and execute arbitrary local PHP files via a crafted parameter in a URL, aka Directory Traversal.
How severe is CVE-2017-10993?
CVE-2017-10993 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-10993?
Check the references section above for vendor advisories and patch information. Affected products include: Contao Contao Cms.