Here you will find a list of vulnerabilities that have already been found and fixed in Contao.
Information disclosure in the back end
CVE ID: CVE-2019-19712
Back end users can manipulate the details view URL to show pages and articles that have not been enabled for them.
Contao 4.4 up to 4.4.45
Contao 4.8 up to 4.8.5
Update to Contao 4.4.46 or 4.8.6.
Back to the overview.
If you think that you have found a security issue in Contao, please report it according to our security policy.