Vulnerability GHSA-qqfq-7cpp-hcqj
Medium Risk
MEDIUM RISK
CVSS Score: 4.3
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
1 year ago
August 28, 2025 at 02:58 PM UTC
Contao does not properly manage privileges for page and article fields
5.3.0 - 5.3.37 and 5.4.0 - 5.4.14 and 5.5.0 - 5.5.16 and 5.6.0
5.3.0 - 5.3.37 and 5.4.0 - 5.4.14 and 5.5.0 - 5.5.16 and 5.6.0
Summary
Contao does not properly manage privileges for page and article fields
Details
Impact
Under certain conditions, back end users may be able to edit fields of pages and articles without having the necessary permissions.
Patches
Update to Contao 5.3.38 or 5.6.1.
Workarounds
None.
For more information
If you have any questions or comments about this advisory, open an issue in contao/contao.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Low Risk
3 days ago
Contao: Server-Side Request Forgery (SSRF) via Unvalidated RSS Feed URL in Feed Reader Module
5.3.35 - 5.3.47 and 5.4.0 - 5.4.14 and 5.5.0 - 5.5.16 and 5.6.0 - 5.6.11 and 5.7.0 - 5.7.8 GHSA-87mg-5grr-rhwh
5.3.35 - 5.3.47 and 5.4.0 - 5.4.14 and 5.5.0 - 5.5.16 and 5.6.0 - 5.6.11 and 5.7.0 - 5.7.8 GHSA-87mg-5grr-rhwh
Low Risk
3 days ago
Contao: Server-Side Request Forgery (SSRF) via Unvalidated RSS Feed URL in Feed Reader Module
5.3.35 - 5.3.47 and 5.4.0 - 5.4.14 and 5.5.0 - 5.5.16 and 5.6.0 - 5.6.11 and 5.7.0 - 5.7.8 GHSA-87mg-5grr-rhwh
5.3.35 - 5.3.47 and 5.4.0 - 5.4.14 and 5.5.0 - 5.5.16 and 5.6.0 - 5.6.11 and 5.7.0 - 5.7.8 GHSA-87mg-5grr-rhwh
Low Risk
1 month ago
Contao: Possible path traversal in job download URIs
5.7.0 - 5.7.6 GHSA-grm4-wm43-9jh5
5.7.0 - 5.7.6 GHSA-grm4-wm43-9jh5
Low Risk
1 month ago
Contao: Possible path traversal in job download URIs
5.7.0 - 5.7.6 GHSA-grm4-wm43-9jh5
5.7.0 - 5.7.6 GHSA-grm4-wm43-9jh5
Low Risk
1 month ago
Contao crawler leaks auth credentials to external hosts
4.13.0 - 4.13.58 and 5.0.0 - 5.0.10 and 5.1.0 - 5.1.11 and 5.2.0 - 5.2.10 and 5.3.0 - 5.3.46 and 5.4.0 - 5.4.14 and 5.5.0 - 5.5.16 and 5.6.0 - 5.6.11 and 5.7.0 - 5.7.6 GHSA-3mr9-p497-58f6
4.13.0 - 4.13.58 and 5.0.0 - 5.0.10 and 5.1.0 - 5.1.11 and 5.2.0 - 5.2.10 and 5.3.0 - 5.3.46 and 5.4.0 - 5.4.14 and 5.5.0 - 5.5.16 and 5.6.0 - 5.6.11 and 5.7.0 - 5.7.6 GHSA-3mr9-p497-58f6
Impacted packages
Timeline
Published
1 year ago
August 28, 2025 at 02:58 PM UTC
Fixed (5.3.38)
1 year ago
August 28, 2025 at 09:34 AM UTC
Fixed (5.3.38)
1 year ago
August 28, 2025 at 09:42 AM UTC
Fixed (5.6.1)
1 year ago
August 28, 2025 at 09:57 AM UTC
Fixed (5.6.1)
1 year ago
August 28, 2025 at 10:08 AM UTC
Last Modified
1 year ago
August 28, 2025 at 07:37 PM UTC