Vulnerability GHSA-mfxh-vp55-7gc6
Summary
Contao: The registration module re-sends activation mails
Details
ModuleRegistration::compile() reaches its follow-up registration branch on any POST to a page carrying the module. That branch checks neither FORM_SUBMIT nor the captcha result computed immediately above it, and resendActivationMail() leads to OptInToken::send(), which has no rate limit at all.
Impact
Anyone on the internet can make a Contao installation send unlimited mail to an address of their choosing, from the site's own sender and reputation, at one outbound message per HTTP request. That is both a nuisance for the recipient and a deliverability risk for the site operator. The same request is a reliable account oracle for "this address has a pending registration on this site", which is exactly the sort of membership fact a public site is usually expected not to disclose.
Honest bound. The target must have an unconfirmed registration, that is tl_member.disable = 1 together with an unconfirmed reg- opt-in token. An attacker can create that state for an arbitrary address, since registration requires no ownership proof, but on a site where reg_activate is off the branch is unreachable.
Related Vulnerabilities
Other vulnerabilities affecting the same packages