CVE-2024-45612
Last modified
CVE-2024-45612 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. Contao is an Open Source CMS. In affected versions an untrusted user can inject insert tags into the canonical tag, which are then replaced on the web page (front end). EPSS estimates a 0.30% chance of exploitation in the next 30 days.
Description
Contao is an Open Source CMS. In affected versions an untrusted user can inject insert tags into the canonical tag, which are then replaced on the web page (front end). Users are advised to update to Contao 4.13.49, 5.3.15 or 5.4.3. Users unable to upgrade should disable canonical tags in the root page settings.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Contao | Contao | >= 4.13.0, < 4.13.49 |
| Contao | Contao | >= 5.3.0, < 5.3.15 |
| Contao | Contao | >= 5.4.0, < 5.4.3 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-45612?
How severe is CVE-2024-45612?
How do I fix CVE-2024-45612?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-45607whatsapp-api-js is a TypeScript server agnostic Whatsapp's O…5.3
- CVE-2024-45608GLPI is a free asset and IT management software package. An …8.8
- CVE-2024-45609GLPI is a Free Asset and IT Management Software package, Dat…6.1
- CVE-2024-4561 In WhatsUp Gold versions released before 2023.1.2 , a bli…5.3
- CVE-2024-45610GLPI is an open-source asset and IT management software pack…6.1
- CVE-2024-45611GLPI is an open-source asset and IT management software pack…5.4
- CVE-2024-45613CKEditor 5 is a JavaScript rich-text editor. Starting in ver…6.1
- CVE-2024-45614Puma is a Ruby/Rack web server built for parallelism. In aff…5.4
- CVE-2024-45615A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 m…3.9
- CVE-2024-45616A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 m…3.9
- CVE-2024-45617A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 m…3.9
- CVE-2024-45618A vulnerability was found in pkcs15-init in OpenSC. An attac…3.9
Are you affected by CVE-2024-45612?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
