Impact
The vulnerability is a misconfiguration of the Symfony voter system in Contao CMS versions 5.7.1 through 5.7.12. The preview access voter is registered under the wrong class name, causing the ownership check to be bypassed. As a result, any non‑admin backend user who has the preview_link module enabled can list all tl_preview_link records, retrieve signed URLs created by other users, and use those URLs to view unpublished pages without proper page permissions. The flaw allows disclosure of unpublished content but does not enable editing or deletion of the links.
Affected Systems
Contao installations running any version from 5.7.1 up to and including 5.7.12 are affected. Versions before 5.7.1 and the release that fixed the bug, 5.7.12 and later, are not impacted. The issue is specific to the core bundle’s services.yaml where the voter class is incorrectly referenced.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate impact. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting limited evidence of exploitation. Attackers can exercise this flaw only if they have valid backend credentials and the preview_link module enabled for their account; thus the attack surface is confined to authorized users of the CMS. Because the exploit requires no special network access or privileges beyond those already held by the user, the overall risk is considered moderate but only relevant to environments where non‑admin users are granted preview_link access.
OpenCVE Enrichment
Github GHSA