Back end users can manipulate the details view URL to show pages and articles that have not been enabled for them.
Update to Contao 4.4.46 or 4.8.6.
None.
https://contao.org/en/security-advisories/information-disclosure-in-the-back-end
If you have any questions or comments about this advisory, open an issue in contao/contao.
{ "nvd_published_at": "2019-12-17T14:15:18Z", "cwe_ids": [ "CWE-276" ], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2019-12-17T19:35:52Z" }