GHSA-mfxh-vp55-7gc6MediumCVSS 5.3

Contao: The registration module re-sends activation mails

Published
October 9, 2026
Last Modified
October 9, 2026

🔗 CVE IDs covered (1)

📋 Description

ModuleRegistration::compile() reaches its follow-up registration branch on any POST to a page carrying the module. That branch checks neither FORM_SUBMIT nor the captcha result computed immediately above it, and resendActivationMail() leads to OptInToken::send(), which has no rate limit at all.

Impact

Anyone on the internet can make a Contao installation send unlimited mail to an address of their choosing, from the site's own sender and reputation, at one outbound message per HTTP request. That is both a nuisance for the recipient and a deliverability risk for the site operator. The same request is a reliable account oracle for "this address has a pending registration on this site", which is exactly the sort of membership fact a public site is usually expected not to disclose.

Honest bound. The target must have an unconfirmed registration, that is tl_member.disable = 1 together with an unconfirmed reg- opt-in token. An attacker can create that state for an arbitrary address, since registration requires no ownership proof, but on a site where reg_activate is off the branch is unreachable.

🎯 Affected products2

  • composer/contao/core-bundle:>= 4.1.0, < 5.3.50
  • composer/contao/core-bundle:>= 5.4.0-RC1, < 5.7.12

🔗 References (5)