Impact
Contao CMS implements a CSRF protection mechanism that validates the REQUEST_TOKEN only for POST requests, while the GET guard is triggered only when an act parameter is present. Backend operations dispatched through the key parameter can therefore be executed without a CSRF token when a legitimate backend user opens an attacker‑controlled URL. This flaw allows an attacker to induce the authenticated user to perform destructive or state‑changing actions such as deleting records, changing settings, or other administrative operations. The impact is limited to actions available to the user, so it does not grant privilege escalation but can compromise data integrity and availability.
Affected Systems
The vulnerability affects Contao CMS versions 4.0.0 through 5.3.49 and all releases prior to 5.7.12. Versions 5.3.50 and 5.7.12 contain the fix and are not vulnerable.
Risk and Exploitability
The CVSS score is 3.5, indicating a low severity. No EPSS data is available, and the issue is not listed in the CISA KEV catalog. The likely attack vector is a compromised or captive backend user being redirected to a malicious URL that relies on the GET request guard to trigger backend actions. Because the flaw requires an authenticated session, exploitation chances are moderate but the consequences are limited to the scope of the compromised account. Tailoring of the malicious URL remains essential for successful exploitation.
OpenCVE Enrichment
Github GHSA