CVE-2022-24899
Last modified
CVE-2022-24899 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. Contao is a powerful open source CMS that allows you to create professional websites and scalable web applications. In versions of Contao prior to 4.13.3 it is possible to inject code into the canonical tag. EPSS estimates a 3.72% chance of exploitation in the next 30 days.
Description
Contao is a powerful open source CMS that allows you to create professional websites and scalable web applications. In versions of Contao prior to 4.13.3 it is possible to inject code into the canonical tag. As a workaround users may disable canonical tags in the root page settings.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Contao | Contao | >= 4.13.0, <= 4.13.2 |
References
- https://github.com/contao/contao/commit/199206849a87ddd0fa5cf674eb3c58292fd8366cPatch, Third Party Advisory
- https://github.com/contao/contao/security/advisories/GHSA-m8x6-6r63-qvj2Third Party Advisory
- https://github.com/contao/contao/commit/199206849a87ddd0fa5cf674eb3c58292fd8366cPatch, Third Party Advisory
- https://github.com/contao/contao/security/advisories/GHSA-m8x6-6r63-qvj2Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-24899?
How severe is CVE-2022-24899?
How do I fix CVE-2022-24899?
Are you affected by CVE-2022-24899?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
