Contao is an Open Source CMS. In versions starting from 5.0.0 and prior to 5.3.38 and 5.6.1, the table access voter in the back end doesn't check if a user is allowed to access the corresponding module. This issue has been patched in versions 5.3.38 and 5.6.1. A workaround involves not relying solely on the voter and additionally to check USER_CAN_ACCESS_MODULE.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-284"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/57xxx/CVE-2025-57758.json"
}{
"cpe": "cpe:2.3:a:contao:contao:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "5.3.0"
},
{
"fixed": "5.3.38"
},
{
"introduced": "5.4.0"
},
{
"fixed": "5.6.1"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
]
}