GHSA-x2rp-9qf7-2fmqMediumCVSS 5.3

Contao: Protected page content is disclosed to anonymous visitors after contao.search.index_protected is disabled

Published
October 9, 2026
Last Modified
October 9, 2026

🔗 CVE IDs covered (1)

📋 Description

ModuleSearch decides whether to filter protected pages out of search results based on the current value of contao.search.index_protected, but the authorisation data lives per row in tl_search. Turning the setting off removes the filter without removing the rows, so protected pages that were indexed while it was on are returned to unauthenticated visitors such as title, URL and context snippet, even though the pages themselves still answer 401.

Impact

Disclosure of member-only page titles, URLs and indexed text to unauthenticated visitors through the site search. The pages themselves remain access-controlled, so this is not a page-access bypass.

Credits

This security vulnerability was found by @iRevivalx .

🎯 Affected products2

  • composer/contao/core-bundle:>= 4.0.0, < 5.3.50
  • composer/contao/core-bundle:>= 5.4.0-RC1, < 5.7.12

🔗 References (5)