SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-24899

Contao is a powerful open source CMS that allows you to create professional websites and scalable web applications.

MEDIUM 6.1EPSS 4.48%

Does this matter?

Lower severity and a low EPSS score (4.48%). Track it; it rarely justifies an emergency change on its own.

Description

Contao is a powerful open source CMS that allows you to create professional websites and scalable web applications. In versions of Contao prior to 4.13.3 it is possible to inject code into the canonical tag. As a workaround users may disable canonical tags in the root page settings.

CVSS 3.1
6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
4.48% probability · 91th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
contao/contao
Source
security-advisories@github.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.