Back end users can manipulate the details view URL to show pages and articles that have not been enabled for them.
Update to Contao 4.4.46 or 4.8.6.
None.
https://contao.org/en/security-advisories/information-disclosure-in-the-back-end
If you have any questions or comments about this advisory, open an issue in contao/contao.
{
"cwe_ids": [
"CWE-276"
],
"github_reviewed": true,
"github_reviewed_at": "2019-12-17T19:35:52Z",
"nvd_published_at": "2019-12-17T14:15:18Z",
"severity": "MODERATE"
}