Contao 是一个开源的内容管理系统(CMS)。从版本 5.7.1 到 5.7.12, 中注册了预览访问 voters,将其类名声明为 ,但实际提供的类是 。由于 Symfony 的 voter 自动配置机制无法匹配正确的类名,因此会省略自动配置并移除该私有服务,导致 方法无法正确实施所有权检查。 具有 模块权限的非管理员后端用户能够列出所有的 记录,获取其他用户创建的已签名分享链接,并利用这些链接在缺乏页面权限的情况下查看未发布的页面(通过 功能)。该安全公告并未涉及对他人链接的编辑或删除权限问题。此问题已在版
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107845 | 9.3 CRITICAL | Contao: Cross-site scripting in the comments bundle |
| CVE-2026-107842 | 5.3 MEDIUM | Contao: Protected page content is disclosed to anonymous visitors after contao.search.inde |
| CVE-2026-107844 | 5.3 MEDIUM | Contao: Path traversal in the images controller |
| CVE-2026-107843 | 5.3 MEDIUM | Contao: The registration module re-sends activation mails on any unauthenticated POST, wit |
| CVE-2026-107851 | 4.3 MEDIUM | Contao: Improper access control in the table access voter |
| CVE-2026-107848 | 3.5 LOW | Contao: Cross-site request forgery in custom backend actions |
No comments yet