Vulnerability Description
Contao is a powerful open source CMS that allows you to create professional websites and scalable web applications. In versions of Contao prior to 4.13.3 it is possible to inject code into the canonical tag. As a workaround users may disable canonical tags in the root page settings.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Contao | Contao | >= 4.13.0, <= 4.13.2 |
Related Weaknesses (CWE)
References
- https://contao.org/en/security-advisories/cross-site-scripting-via-canonical-urlVendor Advisory
- https://github.com/contao/contao/commit/199206849a87ddd0fa5cf674eb3c58292fd8366cPatchThird Party Advisory
- https://github.com/contao/contao/security/advisories/GHSA-m8x6-6r63-qvj2Third Party Advisory
- https://contao.org/en/security-advisories/cross-site-scripting-via-canonical-urlVendor Advisory
- https://github.com/contao/contao/commit/199206849a87ddd0fa5cf674eb3c58292fd8366cPatchThird Party Advisory
- https://github.com/contao/contao/security/advisories/GHSA-m8x6-6r63-qvj2Third Party Advisory
FAQ
What is CVE-2022-24899?
CVE-2022-24899 is a vulnerability with a CVSS score of 7.2 (HIGH). Contao is a powerful open source CMS that allows you to create professional websites and scalable web applications. In versions of Contao prior to 4.13.3 it is possible to inject code into the canonic...
How severe is CVE-2022-24899?
CVE-2022-24899 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-24899?
Check the references section above for vendor advisories and patch information. Affected products include: Contao Contao.