{"id":"CVE-2019-19712","details":"Contao 4.0 through 4.8.5 has Insecure Permissions. Back end users can manipulate the details view URL to show pages and articles that have not been enabled for them.","aliases":["GHSA-4mvc-qc5w-v5qr"],"modified":"2026-08-07T14:52:56.854865Z","published":"2019-12-17T14:15:18.153Z","references":[{"type":"ADVISORY","url":"https://contao.org/en/news.html"},{"type":"ADVISORY","url":"https://contao.org/en/security-advisories/information-disclosure-in-the-back-end.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/contao/contao","events":[{"introduced":"da8a867d8335c4ca55e5085dac11f1fecd12650e"},{"last_affected":"0dae4caadb79f1581d1851d849955929318bc7d9"},{"introduced":"879e05ecc75a6bf70aabc1c3d867eb420f291f60"},{"last_affected":"e2234567e8a17ff151137c288b14591213652195"},{"introduced":"84b2fe637d5ead531f117f26b48d1b9de8df4074"},{"last_affected":"b4dda036c2c0fc7d17c1aa402eaacf6b5dc335fc"}],"database_specific":{"cpe":["cpe:2.3:a:contao:contao:*:*:*:*:*:*:*:*","cpe:2.3:a:contao:contao:4.0:*:*:*:*:*:*:*","cpe:2.3:a:contao:contao:4.1:*:*:*:*:*:*:*","cpe:2.3:a:contao:contao:4.2:*:*:*:*:*:*:*","cpe:2.3:a:contao:contao:4.3:*:*:*:*:*:*:*","cpe:2.3:a:contao:contao:4.5:*:*:*:*:*:*:*","cpe:2.3:a:contao:contao:4.6:*:*:*:*:*:*:*","cpe:2.3:a:contao:contao:4.7:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"4.4.0"},{"last_affected":"4.4.45"},{"introduced":"4.8"},{"last_affected":"4.8.5"},{"introduced":"4.0"},{"last_affected":"4.0"},{"introduced":"4.1"},{"last_affected":"4.1"},{"introduced":"4.2"},{"last_affected":"4.2"},{"introduced":"4.3"},{"last_affected":"4.3"},{"introduced":"4.5"},{"last_affected":"4.5"},{"introduced":"4.6"},{"last_affected":"4.6"},{"introduced":"4.7"},{"last_affected":"4.7"}],"source":["CPE_RANGE","CPE_STRING"]}}],"versions":["4.0","4.1","4.2","4.3","4.5","4.6","4.7","4.8.5","4.8.4","4.8.3","4.8.2","4.8.1","4.8.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-19712.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"}]}