天下漏洞,尽知其名
MEDIUM 重点关注

CVE-2026-107843 Contao 注册模块邮件轰炸与用户枚举漏洞

影响未授权攻击者可反复触发激活邮件并枚举待确认注册用户

AI 研判

Contao CMS 的注册模块在 compile() 方法中,对包含注册模块页面的任意 POST 请求都会进入后续注册分支,且未校验 FORM_SUBMIT 或前置验证码结果。攻击者可借此调用 resendActivationMail(),在无速率限制的情况下反复发送激活邮件,并判断某地址是否存在待确认注册。

影响范围

Contao

漏洞详情

漏洞类型为访问控制不当与资源滥用。成因是 ModuleRegistration::compile() 未验证表单提交标识和验证码即进入重发激活邮件分支,且 OptInToken::send() 缺少速率限制。利用方式为向注册页面发送特制 POST 请求,触发对目标邮箱的重复激活邮件,并通过响应差异判断该邮箱是否存在未确认注册。

利用条件与风险

利用前提是目标启用了 reg_activate,且目标地址存在未确认注册与 opt-in token。实战中可被用于邮件轰炸、骚扰用户及枚举已注册但未激活的账号,CVSS 5.3 属中危。

修复建议

官方已在 5.3.50 和 5.7.12 版本修复,建议升级至该版本或更高。临时缓解可对注册模块的激活邮件重发接口增加速率限制,并确保校验 FORM_SUBMIT 与验证码结果。

原始情报

Contao is an Open Source CMS. From version 4.1.0 until 5.3.50 and 5.7.12, ModuleRegistration::compile() enters its follow-up registration branch on any POST to a page containing the registration module without verifying FORM_SUBMIT or the preceding captcha result. resendActivationMail() can then invoke OptInToken::send() without rate limiting, allowing an unauthenticated attacker to cause repeated activation emails to be sent to an address with a pending registration and to determine whether that pending registration exists. The branch is reachable only when reg_activate is enabled and the target has an unconfirmed registration and opt-in token. This issue is fixed in versions 5.3.50 and 5.7.12.