PT-2025-35104 · Contao · Contao

Leo Feyer

·

Published

2025-08-28

·

Updated

2025-08-28

·

CVE-2025-57758

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Contao versions 5.0.0 through 5.3.37 Contao versions 5.6.0 through 5.6.0
Description: The table access voter in the back end does not verify if a user has permission to access the corresponding module. As a workaround, do not solely rely on the voter and additionally check USER CAN ACCESS MODULE.
Recommendations: Update to Contao version 5.3.38. Update to Contao version 5.6.1. As a workaround, do not rely solely on the voter and additionally check USER CAN ACCESS MODULE.

Exploit

Fix

LPE

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2025-57758
GHSA-7M47-R75R-CX8V

Affected Products

Contao