Contao is an Open Source CMS. In versions starting from 5.3.0 and prior to 5.3.38 and 5.6.1, under certain conditions, back end users may be able to edit fields of pages and articles without having the necessary permissions. This issue has been patched in versions 5.3.38 and 5.6.1. There are no workarounds.
References
Link | Resource |
---|---|
https://contao.org/en/security-advisories/improper-privilege-management-for-page-and-article-fields | Vendor Advisory |
https://github.com/contao/contao/commit/80ee7db12d55ad979d9b1b180f273d4e2668851f | Patch |
https://github.com/contao/contao/security/advisories/GHSA-qqfq-7cpp-hcqj | Patch Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
02 Sep 2025, 17:36
Type | Values Removed | Values Added |
---|---|---|
First Time |
Contao
Contao contao |
|
CPE | cpe:2.3:a:contao:contao:*:*:*:*:*:*:*:* | |
References | () https://contao.org/en/security-advisories/improper-privilege-management-for-page-and-article-fields - Vendor Advisory | |
References | () https://github.com/contao/contao/commit/80ee7db12d55ad979d9b1b180f273d4e2668851f - Patch | |
References | () https://github.com/contao/contao/security/advisories/GHSA-qqfq-7cpp-hcqj - Patch, Third Party Advisory |
28 Aug 2025, 17:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-08-28 17:15
Updated : 2025-09-02 17:36
NVD link : CVE-2025-57759
Mitre link : CVE-2025-57759
CVE.ORG link : CVE-2025-57759
JSON object : View
Products Affected
contao
- contao
CWE
CWE-269
Improper Privilege Management