A logged in back end user can include arbitrary existing PHP files by manipulating an URL parameter
Contao 3.x before 3.5.37, 4.4.x before 4.4.31 and 4.6.x before 4.6.11 has Incorrect Access Control.
Contao before 4.5.7 has XSS in the system log.
Impact
Back end users can manipulate the details view URL to show pages and articles that have not been enabled for them.
Patches
Update to Contao 4.4.46 or 4.8.6.
Workarounds
None.
References
https://contao.org/en/security-advisories/information-disclosure-in-the-back-end
For more information
If you have any questions or comments about this advisory, open an issue in contao/contao.