Description
Contao 4.0 through 4.8.5 allows PHP local file inclusion. A back end user with access to the form generator can upload arbitrary files and execute them on the server.
Remediation
References
Related Vulnerabilities
WordPress Plugin Booking Calendar Contact Form Cross-Site Scripting (1.0.24)
Oracle JRE CVE-2012-0502 Vulnerability (CVE-2012-0502)
WordPress Plugin Count per Day Multiple Vulnerabilities (3.5.6)
WordPress Plugin Indieweb Post Kinds Cross-Site Scripting (1.3.1)
Craft CMS Improper Authentication Vulnerability (CVE-2024-41800)