Improper Permission Management in Contao Open Source CMS
CVE-2025-57759
4.3MEDIUM
What is CVE-2025-57759?
Contao Open Source CMS has a vulnerability that allows back end users to edit fields of pages and articles without the appropriate permissions under specific conditions. This flaw affects versions starting from 5.3.0 up through 5.3.38 and 5.6.1. Patches have been released in newer versions to address this issue, but no workarounds are available for those still using the affected versions.
Affected Version(s)
contao >= 5.3.0, < 5.3.38 < 5.3.0, 5.3.38
contao >= 5.4.0-RC1, < 5.6.1 < 5.4.0-RC1, 5.6.1