VulnerabilityModified
CVE-2022-24899
Contao is a powerful open source CMS that allows you to create professional websites and scalable web applications.
MEDIUM 6.1EPSS 4.48%
Does this matter?
Lower severity and a low EPSS score (4.48%). Track it; it rarely justifies an emergency change on its own.
Description
Contao is a powerful open source CMS that allows you to create professional websites and scalable web applications. In versions of Contao prior to 4.13.3 it is possible to inject code into the canonical tag. As a workaround users may disable canonical tags in the root page settings.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 4.48% probability · 91th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- contao/contao
- Source
- security-advisories@github.com
References
- https://contao.org/en/security-advisories/cross-site-scripting-via-canonical-url.htmlVendor Advisory
- https://github.com/contao/contao/commit/199206849a87ddd0fa5cf674eb3c58292fd8366cPatch, Third Party Advisory
- https://github.com/contao/contao/security/advisories/GHSA-m8x6-6r63-qvj2Third Party Advisory
- https://contao.org/en/security-advisories/cross-site-scripting-via-canonical-url.htmlVendor Advisory
- https://github.com/contao/contao/commit/199206849a87ddd0fa5cf674eb3c58292fd8366cPatch, Third Party Advisory
- https://github.com/contao/contao/security/advisories/GHSA-m8x6-6r63-qvj2Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.