PT-2026-109306 · Contao · Contao
CVE-2026-107848
·
Published
2026-10-09
·
Updated
2026-10-09
CVSS v3.1
3.5
Low
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Contao versions 4.0.0 through 5.3.49
Contao versions 5.7.0 through 5.7.11
Description
Cross-Site Request Forgery (CSRF) occurs because the
RequestTokenListener function validates the REQUEST TOKEN only for POST requests. While a declarative GET guard exists, it only executes when an act parameter is present. Consequently, backend actions dispatched via the key parameter can be executed without a CSRF token if an authenticated backend user loads an attacker-controlled URL. This allows an attacker to perform state-changing or destructive actions on behalf of the authenticated user, limited to the modules the user has permission to access.Recommendations
Update to version 5.3.50.
Update to version 5.7.12.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Contao