Impact
The vulnerability arises from an improper use of caching in TableAccessVoter::hasAccessToModule(), which records authorization decisions using only a hashed token and ignores the database table being accessed. This allows a backend user to gain read, create, update, or delete privileges on tables outside of their assigned module permissions, potentially exposing member or newsletter-subscriber data. The flaw is an access control weakness that can enable privilege escalation and data leakage.
Affected Systems
Contao CMS, version 5.7.0 through 5.7.12. Any installation of these versions is affected; the issue was fixed in version 5.7.12.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves a low‑privileged backend user exploiting the flawed token caching to access unauthorized tables. Once an authorizing request is made for an allowed table, a subsequent request for a disallowed table will be incorrectly granted due to the cached decision and conversion of an abstention into a grant by DefaultDataContainerVoter.
OpenCVE Enrichment
Github GHSA