CVE-2022-24899
Cross site scripting via canonical tag
Record summary
CVE-2022-24899 has a selected CVSS score of 7.2 (high); EIP currently links 1 Nuclei template.
Description
Contao is a powerful open source CMS that allows you to create professional websites and scalable web applications. In versions of Contao prior to 4.13.3 it is possible to inject code into the canonical tag. As a workaround users may disable canonical tags in the root page settings.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 23, 2025 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
contaoBrowse contao / contao | CVE List | < 4.13.3 | affected |
contao/contaoBrowse Packagist / contao/contao | GitHub Advisory | 4.13.0 to < 4.13.3 · Fixed in 4.13.3 | affected |
contao/core-bundleBrowse Packagist / contao/core-bundle | GitHub Advisory | 4.13.0 to < 4.13.3 · Fixed in 4.13.3 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMContao <4.13.3 - Cross-Site ScriptingCVSS 6.1
Contao prior to 4.13.3 contains a cross-site scripting vulnerability. It is possible to inject arbitrary JavaScript code into the canonical tag.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute malicious scripts in a victim's browser, leading to potential data theft, session hijacking, or defacement of the affected website.
Remediation
As a workaround, users may disable canonical tags in the root page settings.
Source: ProjectDiscovery