VulnerabilityModified
CVE-2019-19712
Contao 4.0 through 4.8.5 has Insecure Permissions.
MEDIUM 5.3EPSS 0.88%
Does this matter?
Lower severity and a low EPSS score (0.88%). Track it; it rarely justifies an emergency change on its own.
Description
Contao 4.0 through 4.8.5 has Insecure Permissions. Back end users can manipulate the details view URL to show pages and articles that have not been enabled for them.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.88% probability · 57th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-276
- Affected
- contao/contao
- Source
- cve@mitre.org
References
- https://contao.org/en/news.htmlRelease Notes, Vendor Advisory
- https://contao.org/en/security-advisories/information-disclosure-in-the-back-end.htmlVendor Advisory
- https://contao.org/en/news.htmlRelease Notes, Vendor Advisory
- https://contao.org/en/security-advisories/information-disclosure-in-the-back-end.htmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.