Description
Contao 4.0 through 4.8.5 has Insecure Permissions. Back end users can manipulate the details view URL to show pages and articles that have not been enabled for them.
Remediation
References
Related Vulnerabilities
Drupal Improper Input Validation Vulnerability (CVE-2012-5653)
WordPress Plugin Candidate Application Form Arbitrary File Download (1.0)
Drupal Core 9.0.x Cross-Site Scripting (9.0.0 - 9.0.11)
MediaWiki Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2014-3455)
Apache HTTP Server Out-of-bounds Read Vulnerability (CVE-2026-43951)