{"id":"CVE-2019-19745","details":"Contao 4.0 through 4.8.5 allows PHP local file inclusion. A back end user with access to the form generator can upload arbitrary files and execute them on the server.","aliases":["GHSA-wjx8-cgrm-hh8p"],"modified":"2026-08-07T14:52:56.362621Z","published":"2019-12-17T15:15:25.957Z","references":[{"type":"ADVISORY","url":"https://contao.org/en/news.html"},{"type":"ADVISORY","url":"https://contao.org/en/security-advisories/unrestricted-file-uploads.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/contao/contao","events":[{"introduced":"da8a867d8335c4ca55e5085dac11f1fecd12650e"},{"last_affected":"0dae4caadb79f1581d1851d849955929318bc7d9"},{"introduced":"879e05ecc75a6bf70aabc1c3d867eb420f291f60"},{"last_affected":"e2234567e8a17ff151137c288b14591213652195"},{"introduced":"84b2fe637d5ead531f117f26b48d1b9de8df4074"},{"last_affected":"b4dda036c2c0fc7d17c1aa402eaacf6b5dc335fc"}],"database_specific":{"cpe":["cpe:2.3:a:contao:contao:*:*:*:*:*:*:*:*","cpe:2.3:a:contao:contao:4.0:*:*:*:*:*:*:*","cpe:2.3:a:contao:contao:4.1:*:*:*:*:*:*:*","cpe:2.3:a:contao:contao:4.2:*:*:*:*:*:*:*","cpe:2.3:a:contao:contao:4.3:*:*:*:*:*:*:*","cpe:2.3:a:contao:contao:4.5:*:*:*:*:*:*:*","cpe:2.3:a:contao:contao:4.6:*:*:*:*:*:*:*","cpe:2.3:a:contao:contao:4.7:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"4.4"},{"last_affected":"4.4.45"},{"introduced":"4.8"},{"last_affected":"4.8.5"},{"introduced":"4.0"},{"last_affected":"4.0"},{"introduced":"4.1"},{"last_affected":"4.1"},{"introduced":"4.2"},{"last_affected":"4.2"},{"introduced":"4.3"},{"last_affected":"4.3"},{"introduced":"4.5"},{"last_affected":"4.5"},{"introduced":"4.6"},{"last_affected":"4.6"},{"introduced":"4.7"},{"last_affected":"4.7"}],"source":["CPE_RANGE","CPE_STRING"]}}],"versions":["4.0","4.1","4.2","4.3","4.5","4.6","4.7","4.8.5","4.8.4","4.8.3","4.8.2","4.8.1","4.8.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-19745.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}