Contao 是一个开源的内容管理系统(CMS)。在版本 5.7.0 至 5.7.12 中, 中的 方法在缓存授权决策时仅使用了 (用户安全令牌的哈希值),而忽略了 返回的数据表信息。因此,如果一个请求先检查了用户有权访问的某个数据表,随后又检查另一个用户无权访问的数据表,该投票器(Voter)可能会错误地重用之前“允许访问”的缓存结果;同时, 可能将本应返回的“弃权”(abstention)错误地转换为“允许访问”(grant)。这导致具有低权限的后端用户能够读写、创建、更新或删除超出其模块权限范围的数据表中的记
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107845 | 9.3 CRITICAL | Contao: Cross-site scripting in the comments bundle |
| CVE-2026-107842 | 5.3 MEDIUM | Contao: Protected page content is disclosed to anonymous visitors after contao.search.inde |
| CVE-2026-107844 | 5.3 MEDIUM | Contao: Path traversal in the images controller |
| CVE-2026-107843 | 5.3 MEDIUM | Contao: The registration module re-sends activation mails on any unauthenticated POST, wit |
| CVE-2026-107850 | 4.3 MEDIUM | Contao: Improper access control in the preview links module |
| CVE-2026-107848 | 3.5 LOW | Contao: Cross-site request forgery in custom backend actions |
No comments yet