Insecure service configuration In contao/contao
Description
Information disclosure in the Contao backend
Impact
Back end users can manipulate the details view URL to show pages and articles that have not been enabled for them.
Patches
Update to Contao 4.4.46 or 4.8.6.
Workarounds
None.
References
https://contao.org/en/security-advisories/information-disclosure-in-the-back-end
For more information
If you have any questions or comments about this advisory, open an issue in contao/contao.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
packagist | 4.4.46, 4.8.6 | ||
packagist | 4.4.46, 4.8.6 |
Aliases
1. 2. 3. 4. 5.
References
1. 2. 3. 4. 5.