ModuleRegistration::compile() reaches its follow-up registration branch on any POST to a page carrying the module. That branch checks neither FORM_SUBMIT nor the captcha result computed immediately above it, and resendActivationMail() leads to OptInToken::send(), which has no rate limit at all.
Anyone on the internet can make a Contao installation send unlimited mail to an address of their choosing, from the site's own sender and reputation, at one outbound message per HTTP request. That is both a nuisance for the recipient and a deliverability risk for the site operator. The same request is a reliable account oracle for "this address has a pending registration on this site", which is exactly the sort of membership fact a public site is usually expected not to disclose.
Honest bound. The target must have an unconfirmed registration, that is tl_member.disable = 1 together with an unconfirmed reg- opt-in token. An attacker can create that state for an arbitrary address, since registration requires no ownership proof, but on a site where reg_activate is off the branch is unreachable.
{
"cwe_ids": [
"CWE-204",
"CWE-770"
],
"github_reviewed": true,
"github_reviewed_at": "2026-10-09T20:54:04Z",
"nvd_published_at": null,
"severity": "MODERATE"
}