CVE-2025-57759

Source
https://cve.org/CVERecord?id=CVE-2025-57759
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-57759.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-57759
Aliases
Published
2025-08-28T16:32:59.022Z
Modified
2026-04-10T05:31:10.214389Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N CVSS Calculator
Summary
Contao has improper privilege management for page and article fields
Details

Contao is an Open Source CMS. In versions starting from 5.3.0 and prior to 5.3.38 and 5.6.1, under certain conditions, back end users may be able to edit fields of pages and articles without having the necessary permissions. This issue has been patched in versions 5.3.38 and 5.6.1. There are no workarounds.

Database specific
{
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/57xxx/CVE-2025-57759.json",
    "cwe_ids": [
        "CWE-269"
    ]
}
References

Affected packages

Git / github.com/contao/contao

Affected ranges

Type
GIT
Repo
https://github.com/contao/contao
Events
Database specific
{
    "versions": [
        {
            "introduced": "5.3.0"
        },
        {
            "fixed": "5.3.38"
        }
    ]
}
Type
GIT
Repo
https://github.com/contao/contao
Events
Database specific
{
    "versions": [
        {
            "introduced": "5.4.0-RC1"
        },
        {
            "fixed": "5.6.1"
        }
    ]
}

Affected versions

5.*
5.3.0
5.3.1
5.3.10
5.3.11
5.3.12
5.3.13
5.3.14
5.3.15
5.3.16
5.3.17
5.3.18
5.3.19
5.3.2
5.3.20
5.3.21
5.3.22
5.3.23
5.3.24
5.3.25
5.3.26
5.3.27
5.3.28
5.3.29
5.3.3
5.3.30
5.3.31
5.3.32
5.3.33
5.3.34
5.3.35
5.3.36
5.3.37
5.3.4
5.3.5
5.3.6
5.3.7
5.3.8
5.3.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-57759.json"