Description
Contao 4.0 through 4.8.5 has Insecure Permissions. Back end users can manipulate the details view URL to show pages and articles that have not been enabled for them.
Remediation
References
Related Vulnerabilities
MediaWiki URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2017-0363)
WebLogic CVE-2023-22101 Vulnerability (CVE-2023-22101)
WordPress Plugin Our Team Showcase Cross-Site Request Forgery (1.2)
XWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2023-29517)