{"id":"CVE-2019-19712","aliases":["GHSA-4mvc-qc5w-v5qr"],"url":"https://o3.security/vulnerability/CVE-2019-19712","summary":"Information disclosure in the Contao backend","details":"Contao 4.0 through 4.8.5 has Insecure Permissions. Back end users can manipulate the details view URL to show pages and articles that have not been enabled for them.","published":"2019-12-17T14:15:18.153Z","modified":"2026-08-07T14:52:56.854865Z","cvss":{"score":5.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Packagist","name":"contao/core-bundle","fixedVersion":"4.4.46"},{"ecosystem":"Packagist","name":"contao/core-bundle","fixedVersion":"4.8.6"},{"ecosystem":"Packagist","name":"contao/contao","fixedVersion":"4.4.46"},{"ecosystem":"Packagist","name":"contao/contao","fixedVersion":"4.8.6"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://contao.org/en/news.html"},{"type":"ADVISORY","url":"https://contao.org/en/security-advisories/information-disclosure-in-the-back-end.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T14:52:56.854865Z"}}