Impact
The Contao registration module fails to verify that a form has been legitimately submitted or that a captcha challenge was completed. As a result, any unauthenticated POST to a page containing the module will trigger the resendActivationMail pathway, allowing an attacker to cause the system to send activation emails repeatedly to a target address. This lack of input validation and rate limiting permits an attacker to flood the target mailbox and to discover whether a pending registration exists. The flaw is identified as both an information‑leak weakness (CWE‑204) and an improper resource handling weakness (CWE‑770).
Affected Systems
Contao CMS instances running any version from 4.1.0 up to and including 5.3.50 and 5.7.12 are vulnerable. The vulnerability remains when the optional reg_activate feature is enabled and a user has a pending, unconfirmed registration with an opt‑in token. All other Contao versions are not affected by this issue.
Risk and Exploitability
The CVSS base score of 5.3 denotes a moderate impact. While the EPSS score is not available, the lack of authentication, captcha, or rate limiting means an attacker can easily trigger the flaw by repeatedly POSTing to the registration page. The vulnerability is not listed in CISA’s KEV catalog, but the straightforward exploitation path and the potential for large‑scale email flooding make timely remediation important.
OpenCVE Enrichment