Vulnerability Description
Contao is an Open Source CMS. In affected versions an untrusted user can inject insert tags into the canonical tag, which are then replaced on the web page (front end). Users are advised to update to Contao 4.13.49, 5.3.15 or 5.4.3. Users unable to upgrade should disable canonical tags in the root page settings.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Contao | Contao | >= 4.13.0, < 4.13.49 |
Related Weaknesses (CWE)
References
- https://contao.org/en/security-advisories/insert-tag-injection-via-canonical-urlVendor Advisory
- https://github.com/contao/contao/security/advisories/GHSA-2xpq-xp6c-5mgjVendor Advisory
FAQ
What is CVE-2024-45612?
CVE-2024-45612 is a vulnerability with a CVSS score of 5.3 (MEDIUM). Contao is an Open Source CMS. In affected versions an untrusted user can inject insert tags into the canonical tag, which are then replaced on the web page (front end). Users are advised to update to ...
How severe is CVE-2024-45612?
CVE-2024-45612 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-45612?
Check the references section above for vendor advisories and patch information. Affected products include: Contao Contao.