296,108
Total vulnerabilities in the database
The table access voter in the back end doesn't check if a user is allowed to access the corresponding module.
Update to Contao 5.3.38 or 5.6.1.
Do not rely solely on the voter and additionally check USER_CAN_ACCESS_MODULE
.
If you have any questions or comments about this advisory, open an issue in contao/contao.
Software | From | Fixed in |
---|---|---|
![]() |
5.0.0 | 5.3.38 |
![]() |
5.4.0-RC1 | 5.6.1 |
![]() |
5.0.0 | 5.3.38 |
![]() |
5.4.0-RC1 | 5.6.1 |