Contao 是一款开源的内容管理系统(CMS)。在 4.0.0 至 5.3.50 以及 5.7.0 至 5.7.12 版本中, 仅对 POST 请求验证 ,而基于声明式保护的 GET 请求检查仅在存在 参数时才会生效。因此,当已认证的后台用户访问攻击者控制的 URL 时,通过 参数分派的后台操作可以在不提供 CSRF 令牌的情况下执行。受影响的操作范围仅限于该用户可用的模块,本安全公告重点演示的是破坏性或状态变更的操作,而非权限提升。该问题已在版本 5.3.50 和 5.7.12 中得到修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107845 | 9.3 CRITICAL | Contao: Cross-site scripting in the comments bundle |
| CVE-2026-107842 | 5.3 MEDIUM | Contao: Protected page content is disclosed to anonymous visitors after contao.search.inde |
| CVE-2026-107844 | 5.3 MEDIUM | Contao: Path traversal in the images controller |
| CVE-2026-107843 | 5.3 MEDIUM | Contao: The registration module re-sends activation mails on any unauthenticated POST, wit |
| CVE-2026-107851 | 4.3 MEDIUM | Contao: Improper access control in the table access voter |
| CVE-2026-107850 | 4.3 MEDIUM | Contao: Improper access control in the preview links module |
No comments yet