Contao: The registration module re-sends activation mails
🔗 CVE IDs covered (1)
📋 Description
ModuleRegistration::compile() reaches its follow-up registration branch on any POST to a page carrying the module. That branch checks neither FORM_SUBMIT nor the captcha result computed immediately above it, and resendActivationMail() leads to OptInToken::send(), which has no rate limit at all.
Impact
Anyone on the internet can make a Contao installation send unlimited mail to an address of their choosing, from the site's own sender and reputation, at one outbound message per HTTP request. That is both a nuisance for the recipient and a deliverability risk for the site operator. The same request is a reliable account oracle for "this address has a pending registration on this site", which is exactly the sort of membership fact a public site is usually expected not to disclose.
Honest bound. The target must have an unconfirmed registration, that is tl_member.disable = 1 together with an unconfirmed reg- opt-in token. An attacker can create that state for an arbitrary address, since registration requires no ownership proof, but on a site where reg_activate is off the branch is unreachable.
🎯 Affected products2
- composer/contao/core-bundle:>= 4.1.0, < 5.3.50
- composer/contao/core-bundle:>= 5.4.0-RC1, < 5.7.12
🔗 References (5)
- https://github.com/contao/contao/security/advisories/GHSA-mfxh-vp55-7gc6
- https://github.com/contao/contao/commit/2ea6117f9049db7221679251cfc41e67d941a74b
- https://github.com/contao/contao/releases/tag/5.3.50
- https://github.com/contao/contao/releases/tag/5.7.12
- https://github.com/advisories/GHSA-mfxh-vp55-7gc6