CVE-2024-45612

MEDIUM

Contao 4.13.0-4.13.48 - Insert Tag Injection via Canonical URL

Title source: llm
STIX 2.1

Description

Contao is an Open Source CMS. In affected versions an untrusted user can inject insert tags into the canonical tag, which are then replaced on the web page (front end). Users are advised to update to Contao 4.13.49, 5.3.15 or 5.4.3. Users unable to upgrade should disable canonical tags in the root page settings.

References (2)

Core 2

Scores

CVSS v3 5.3
EPSS 0.0029
EPSS Percentile 20.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-20 CWE-74
Status published
Products (2)
contao/contao 4.13.0 - 4.13.49
contao/core-bundle 4.13.0 - 4.13.49Packagist
Published Sep 17, 2024
Tracked Since Feb 18, 2026