Vulnerability GHSA-qqfq-7cpp-hcqj

Medium Risk
MEDIUM RISK
CVSS Score: 4.3
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
1 year ago
August 28, 2025 at 02:58 PM UTC
Contao does not properly manage privileges for page and article fields
5.3.0 - 5.3.37 and 5.4.0 - 5.4.14 and 5.5.0 - 5.5.16 and 5.6.0
5.3.0 - 5.3.37 and 5.4.0 - 5.4.14 and 5.5.0 - 5.5.16 and 5.6.0

Summary

Contao does not properly manage privileges for page and article fields

Details

Impact

Under certain conditions, back end users may be able to edit fields of pages and articles without having the necessary permissions.

Patches

Update to Contao 5.3.38 or 5.6.1.

Workarounds

None.

For more information

If you have any questions or comments about this advisory, open an issue in contao/contao.

Related Vulnerabilities

Other vulnerabilities affecting the same packages

View all vulnerabilities for these packages

Timeline

Published
1 year ago
August 28, 2025 at 02:58 PM UTC
Fixed (5.3.38)
1 year ago
August 28, 2025 at 09:34 AM UTC
Fixed (5.3.38)
1 year ago
August 28, 2025 at 09:42 AM UTC
Fixed (5.6.1)
1 year ago
August 28, 2025 at 09:57 AM UTC
Fixed (5.6.1)
1 year ago
August 28, 2025 at 10:08 AM UTC
Last Modified
1 year ago
August 28, 2025 at 07:37 PM UTC