CVE-2024-45612
Last modified
CVE-2024-45612 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. Contao is an Open Source CMS. In affected versions an untrusted user can inject insert tags into the canonical tag, which are then replaced on the web page (front end). EPSS estimates a 0.30% chance of exploitation in the next 30 days.
Description
Contao is an Open Source CMS. In affected versions an untrusted user can inject insert tags into the canonical tag, which are then replaced on the web page (front end). Users are advised to update to Contao 4.13.49, 5.3.15 or 5.4.3. Users unable to upgrade should disable canonical tags in the root page settings.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Contao | Contao | >= 4.13.0, < 4.13.49 |
| Contao | Contao | >= 5.3.0, < 5.3.15 |
| Contao | Contao | >= 5.4.0, < 5.4.3 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-45612?
How severe is CVE-2024-45612?
How do I fix CVE-2024-45612?
Are you affected by CVE-2024-45612?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
