Under certain conditions, back end users may be able to edit fields of pages and articles without having the necessary permissions.
Update to Contao 5.3.38 or 5.6.1.
None.
If you have any questions or comments about this advisory, open an issue in contao/contao.
| Score | Percentile |
|---|---|
| 0.04% | 11.42% |
| Base score | Version | Severity | Vector |
|---|---|---|---|
| 4.3 | 3.1 | — |
|
| Type | Value |
|---|---|
| GHSA | GHSA-qqfq-7cpp-hcqj ↗ |
| CVE | CVE-2025-57759 ↗ |
| CWE id | Name |
|---|---|
| CWE-269 | Improper Privilege Management |
Vulnerable version ranges and first patched releases as published by GitHub.
| Ecosystem | Package | Vulnerable range | First patched | Vulnerable functions |
|---|---|---|---|---|
| composer | contao/core-bundle | >= 5.3.0, < 5.3.38 | 5.3.38 | — |
| composer | contao/core-bundle | >= 5.4.0-RC1, < 5.6.1 | 5.6.1 | — |
| composer | contao/contao | >= 5.3.0, < 5.3.38 | 5.3.38 | — |
| composer | contao/contao | >= 5.4.0-RC1, < 5.6.1 | 5.6.1 | — |