← voltar
CVE-2025-57758

Contao has improper access control in the back end voters

CVSS 4.3 MEDIUMEPSS 0.2%CWE-284
Contao is an Open Source CMS. In versions starting from 5.0.0 and prior to 5.3.38 and 5.6.1, the table access voter in the back end doesn't check if a user is allowed to access the corresponding module. This issue has been patched in versions 5.3.38 and 5.6.1. A workaround involves not relying solely on the voter and additionally to check USER_CAN_ACCESS_MODULE.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Produtos afetados
contao · contao

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →