5.3
CVE-2025-57757
- EPSS 0.28%
- Veröffentlicht 28.08.2025 16:32:03
- Zuletzt bearbeitet 02.09.2025 17:38:34
- Quelle security-advisories@github.com
- CVE-Watchlists
- Unerledigt
Contao discloses information in the news module
Contao is an Open Source CMS. In versions starting from 5.0.0 and prior to 5.3.38 and 5.6.1, if a news feed contains protected news archives, their news items are not filtered and become publicly available in the RSS feed. This issue has been patched in versions 5.3.38 and 5.6.1. A workaround involves not adding protected news archives to the news feed page.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.28% | 0.196 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CWE-212 Improper Removal of Sensitive Information Before Storage or Transfer
The product stores, transfers, or shares a resource that contains sensitive information, but it does not properly remove that information before the product makes the resource available to unauthorized actors.
https://github.com/contao/contao/security/advisories/GHSA-w53m-gxvg-vx7p
https://github.com/contao/contao/commit/e75f46b11974fbf7a4652e65c19ad6ca84c59271
https://contao.org/en/security-advisories/information-disclosure-in-the-news-module