ZeroHour

CVE-2019-19712

CVSS 3.1
5.3 medium
EPSS
<1%p57
Published
()
Modified
Description

Contao 4.0 through 4.8.5 has Insecure Permissions. Back end users can manipulate the details view URL to show pages and articles that have not been enabled for them.

Vendors
contao
Products
contao
Weakness
CWE-276
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.