Incorrect default permissions in Contao - CVE-2019-19712
Published: December 17, 2019 / Updated: August 8, 2020
Vulnerability identifier: #VU34960
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-19712
CWE-ID: CWE-276
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
Contao 4.0 through 4.8.5 has Insecure Permissions. Back end users can manipulate the details view URL to show pages and articles that have not been enabled for them.
Affected software
Contao
How to mitigate CVE-2019-19712
Install update from vendor's website.