Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7m47-r75r-cx8v

Опубликовано: 28 авг. 2025
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

Contao applies improper access control in the back end voters

Impact

The table access voter in the back end doesn't check if a user is allowed to access the corresponding module.

Patches

Update to Contao 5.3.38 or 5.6.1.

Workarounds

Do not rely solely on the voter and additionally check USER_CAN_ACCESS_MODULE.

For more information

If you have any questions or comments about this advisory, open an issue in contao/contao.

Пакеты

Наименование

contao/core-bundle

composer
Затронутые версииВерсия исправления

>= 5.0.0, < 5.3.38

5.3.38

Наименование

contao/core-bundle

composer
Затронутые версииВерсия исправления

>= 5.4.0-RC1, < 5.6.1

5.6.1

Наименование

contao/contao

composer
Затронутые версииВерсия исправления

>= 5.0.0, < 5.3.38

5.3.38

Наименование

contao/contao

composer
Затронутые версииВерсия исправления

>= 5.4.0-RC1, < 5.6.1

5.6.1

EPSS

Процентиль: 12%
0.0004
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 4.3
nvd
5 месяцев назад

Contao is an Open Source CMS. In versions starting from 5.0.0 and prior to 5.3.38 and 5.6.1, the table access voter in the back end doesn't check if a user is allowed to access the corresponding module. This issue has been patched in versions 5.3.38 and 5.6.1. A workaround involves not relying solely on the voter and additionally to check USER_CAN_ACCESS_MODULE.

EPSS

Процентиль: 12%
0.0004
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-284