Record summary

CVE-2022-24899 has a selected CVSS score of 7.2 (high); EIP currently links 1 Nuclei template.

Description

Contao is a powerful open source CMS that allows you to create professional websites and scalable web applications. In versions of Contao prior to 4.13.3 it is possible to inject code into the canonical tag. As a workaround users may disable canonical tags in the root page settings.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 23, 2025 · Source: CVE List

Affected products and versions

3
ProductSourceVersion rangeStatus
CVE List< 4.13.3affected
GitHub Advisory4.13.0 to < 4.13.3 · Fixed in 4.13.3affected
GitHub Advisory4.13.0 to < 4.13.3 · Fixed in 4.13.3affected

Nuclei templates

1
ProjectDiscoveryMEDIUMContao <4.13.3 - Cross-Site ScriptingCVSS 6.1

Contao prior to 4.13.3 contains a cross-site scripting vulnerability. It is possible to inject arbitrary JavaScript code into the canonical tag.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute malicious scripts in a victim's browser, leading to potential data theft, session hijacking, or defacement of the affected website.

Remediation

As a workaround, users may disable canonical tags in the root page settings.

WeaknessesCWE-79
Authorsritikchaddha
Template tagscvecve2022contaoxsshuntrvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:contao:contao:*:*:*:*:*:*:*:*
Shodan: title:"Contao"
Shodan: http.title:"contao"
Shodan: http.html:"contao open source cms"
Shodan: cpe:"cpe:2.3:a:contao:contao"
FOFA: body="contao open source cms"
FOFA: title="contao"
Google: intitle:"contao"

Source: ProjectDiscovery

References

7