Information disclosure in the Contao backend
Description
Published by the National Vulnerability Database
Dec 17, 2019
Reviewed
Dec 17, 2019
Published to the GitHub Advisory Database
Dec 17, 2019
Last updated
Apr 22, 2024
Impact
Back end users can manipulate the details view URL to show pages and articles that have not been enabled for them.
Patches
Update to Contao 4.4.46 or 4.8.6.
Workarounds
None.
References
https://contao.org/en/security-advisories/information-disclosure-in-the-back-end
For more information
If you have any questions or comments about this advisory, open an issue in contao/contao.
References