logo

Database

Insecure service configuration In contao/contao

Description

Information disclosure in the Contao backend

Impact

Back end users can manipulate the details view URL to show pages and articles that have not been enabled for them.

Patches

Update to Contao 4.4.46 or 4.8.6.

Workarounds

None.

References

https://contao.org/en/security-advisories/information-disclosure-in-the-back-end

For more information

If you have any questions or comments about this advisory, open an issue in contao/contao.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions