Contao 4.0 through 4.8.5 has Insecure Permissions. Back end users can manipulate the details view URL to show pages and articles that have not been enabled for them.
https://github.com/advisories/GHSA-4mvc-qc5w-v5qr
https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-0776
https://contao.org/en/security-advisories/information-disclosure-in-the-back-end.html