CVE-2025-57758

MEDIUM

Contao < 5.3.38 - Improper Access Control

Title source: rule
STIX 2.1

Description

Contao is an Open Source CMS. In versions starting from 5.0.0 and prior to 5.3.38 and 5.6.1, the table access voter in the back end doesn't check if a user is allowed to access the corresponding module. This issue has been patched in versions 5.3.38 and 5.6.1. A workaround involves not relying solely on the voter and additionally to check USER_CAN_ACCESS_MODULE.

Scores

CVSS v3 4.3
EPSS 0.0004
EPSS Percentile 13.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-284
Status published
Products (3)
contao/contao 5.0.0 - 5.3.38Packagist
contao/contao 5.3.0 - 5.3.38
contao/core-bundle 5.0.0 - 5.3.38Packagist
Published Aug 28, 2025
Tracked Since Feb 18, 2026