Description
Contao 3.x before 3.5.37, 4.4.x before 4.4.31 and 4.6.x before 4.6.11 has Incorrect Access Control.
Remediation
References
Related Vulnerabilities
MediaWiki Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-1581)
WordPress Plugin Ninja Forms with File Uploads Extension Arbitrary File Upload (3.3.0)
PHP Use After Free Vulnerability (CVE-2016-6290)
WordPress Plugin Payment Form for PayPal Pro Multiple Cross-Site Scripting Vulnerabilities (1.0.1)