Contao applies improper access control in the back end voters
Description
Published to the GitHub Advisory Database
Aug 28, 2025
Reviewed
Aug 28, 2025
Published by the National Vulnerability Database
Aug 28, 2025
Last updated
Aug 28, 2025
Impact
The table access voter in the back end doesn't check if a user is allowed to access the corresponding module.
Patches
Update to Contao 5.3.38 or 5.6.1.
Workarounds
Do not rely solely on the voter and additionally check
USER_CAN_ACCESS_MODULE
.For more information
If you have any questions or comments about this advisory, open an issue in contao/contao.
References