Contao is an Open Source CMS. In versions starting from 5.3.0 and prior to 5.3.38 and 5.6.1, under certain conditions, back end users may be able to edit fields of pages and articles without having the necessary permissions. This issue has been patched in versions 5.3.38 and 5.6.1. There are no workarounds.
Metrics
Affected Vendors & Products
References
History
Tue, 02 Sep 2025 17:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:2.3:a:contao:contao:*:*:*:*:*:*:*:* |
Thu, 28 Aug 2025 21:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Contao
Contao contao |
|
Vendors & Products |
Contao
Contao contao |
Thu, 28 Aug 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 28 Aug 2025 16:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Contao is an Open Source CMS. In versions starting from 5.3.0 and prior to 5.3.38 and 5.6.1, under certain conditions, back end users may be able to edit fields of pages and articles without having the necessary permissions. This issue has been patched in versions 5.3.38 and 5.6.1. There are no workarounds. | |
Title | Contao has improper privilege management for page and article fields | |
Weaknesses | CWE-269 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-08-28T17:16:55.904Z
Reserved: 2025-08-19T15:16:22.916Z
Link: CVE-2025-57759

Updated: 2025-08-28T17:16:52.971Z

Status : Analyzed
Published: 2025-08-28T17:15:36.597
Modified: 2025-09-02T17:36:12.837
Link: CVE-2025-57759

No data.

Updated: 2025-08-28T21:21:40Z