Contao is an Open Source CMS. From version 4.0.0 until 5.3.50 and 5.7.12, RequestTokenListener validates REQUEST_TOKEN only for POST requests, while the declarative GET guard runs only when an act parameter is present. Backend actions dispatched through the key parameter can therefore execute without a CSRF token when an authenticated backend user loads an attacker-controlled URL. Reachable actions remain limited to modules available to that user, and the advisory demonstrates destructive or state-changing actions rather than privilege escalation. This issue is fixed in versions 5.3.50 and 5.7.12.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-9ff2-p842-45wq | Contao: Cross-site request forgery in custom backend actions |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 09 Oct 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Contao
Contao contao |
|
| Vendors & Products |
Contao
Contao contao |
Fri, 09 Oct 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Contao is an Open Source CMS. From version 4.0.0 until 5.3.50 and 5.7.12, RequestTokenListener validates REQUEST_TOKEN only for POST requests, while the declarative GET guard runs only when an act parameter is present. Backend actions dispatched through the key parameter can therefore execute without a CSRF token when an authenticated backend user loads an attacker-controlled URL. Reachable actions remain limited to modules available to that user, and the advisory demonstrates destructive or state-changing actions rather than privilege escalation. This issue is fixed in versions 5.3.50 and 5.7.12. | |
| Title | Contao: Cross-site request forgery in custom backend actions | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-09T20:22:12.778Z
Reserved: 2026-10-08T22:34:49.291Z
Link: CVE-2026-107848
No data.
Status : Received
Published: 2026-10-09T21:17:02.617
Modified: 2026-10-09T21:17:02.617
Link: CVE-2026-107848
No data.
OpenCVE Enrichment
Updated: 2026-10-09T21:30:12Z
Weaknesses
Github GHSA