CVE-2022-24899: Cross site scripting via canonical tag
Impact
Untrusted users can inject malicious code into the canonical tag, which is then executed on the web page (front end).
Patches
Update to Contao 4.13.3.
Workarounds
Disable canonical tags in the root page settings.
References
https://contao.org/en/security-advisories/cross-site-scripting-via-canonical-url
For more information
If you have any questions or comments about this advisory, open an issue in contao/contao.
Other sources
Contao is a powerful open source CMS that allows you to create professional websites and scalable web applications. In versions of Contao prior to 4.13.3 it is possible to inject code into the canonical tag. As a workaround users may disable canonical tags in the root page settings.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-24899?
CVE-2022-24899 is a vulnerability in the Contao CMS that allows for cross-site scripting via the canonical URL.
How severe is CVE-2022-24899?
CVE-2022-24899 has a severity level of 6.1 (high).
How can I fix CVE-2022-24899?
To fix CVE-2022-24899, update Contao to version 4.13.3 or later and disable canonical tags in the root page settings.
Where can I find more information about CVE-2022-24899?
You can find more information about CVE-2022-24899 in the Contao security advisory and the GitHub commits and advisories provided in the references.
What is CWE-79?
CWE-79 refers to the Cross-Site Scripting (XSS) vulnerability, which is the type of vulnerability present in CVE-2022-24899.