Description
Contao before 3.5.28 and 4.x before 4.4.1 allows remote attackers to include and execute arbitrary local PHP files via a crafted parameter in a URL, aka Directory Traversal.
Remediation
References
Related Vulnerabilities
WordPress Plugin User Registration, Login & Landing Pages-LeadMagic Cross-Site Scripting (1.2.7)
WordPress Plugin WP Private Content Plus Cross-Site Request Forgery (3.1)
WordPress Plugin SecureMoz Security Audit PHP Object Injection (1.0.5)
Undertow Uncontrolled Resource Consumption Vulnerability (CVE-2019-19343)