MEDIUM
Contao 4.0 through 4.8.5 has Insecure Permissions
Published Dec 17, 2019
5.3
MEDIUMCVSS 3.1
EPSS 0.88%
Description
Contao 4.0 through 4.8.5 has Insecure Permissions. Back end users can manipulate the details view URL to show pages and articles that have not been enabled for them.
Affected products
No data.
OR
- ≥ 4.4.0 · ≤ 4.4.45
- ≥ 4.8 · ≤ 4.8.5
- 4.0
- 4.1
- 4.2
- 4.3
- 4.5
- 4.6
- 4.7
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (8)
- https://contao.org/en/news.html x_refsource_MISCRelease NotesVendor Advisory
- https://contao.org/en/security-advisories/information-disclosure-in-the-back-end.html x_refsource_CONFIRMVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-0776 Advisory
- https://github.com/FriendsOfPHP/security-advisories/blob/master/contao/contao/CVE-2019-19712.yaml
- https://github.com/FriendsOfPHP/security-advisories/blob/master/contao/core-bundle/CVE-2019-19712.yaml
- https://github.com/advisories/GHSA-4mvc-qc5w-v5qr Advisory
- https://github.com/contao/contao/security/advisories/GHSA-4mvc-qc5w-v5qr
- https://nvd.nist.gov/vuln/detail/CVE-2019-19712
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 17, 2019
Updated Aug 5, 2024
Reserved Dec 11, 2019
Link CVE-2019-19712
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2019-0776 GHSA-4MVC-QC5W-V5QR Assigner mitre
Published Dec 17, 2019
Updated Aug 5, 2024
Exploited since n/a
Link EUVD-2019-0776