Contao is an Open Source CMS. In versions starting from 5.3.0 and prior to 5.3.38 and 5.6.1, under certain conditions, back end users may be able to edit fields of pages and articles without having the necessary permissions. This issue has been patched in versions 5.3.38 and 5.6.1. There are no workarounds.
Metrics
Affected Vendors & Products
References
History
Tue, 02 Sep 2025 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:contao:contao:*:*:*:*:*:*:*:* |
Thu, 28 Aug 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Contao
Contao contao |
|
| Vendors & Products |
Contao
Contao contao |
Thu, 28 Aug 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 28 Aug 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Contao is an Open Source CMS. In versions starting from 5.3.0 and prior to 5.3.38 and 5.6.1, under certain conditions, back end users may be able to edit fields of pages and articles without having the necessary permissions. This issue has been patched in versions 5.3.38 and 5.6.1. There are no workarounds. | |
| Title | Contao has improper privilege management for page and article fields | |
| Weaknesses | CWE-269 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-08-28T16:32:59.022Z
Updated: 2025-08-28T17:16:55.904Z
Reserved: 2025-08-19T15:16:22.916Z
Link: CVE-2025-57759
Updated: 2025-08-28T17:16:52.971Z
Status : Analyzed
Published: 2025-08-28T17:15:36.597
Modified: 2025-09-02T17:36:12.837
Link: CVE-2025-57759
No data.