← Back

CVE-2024-45612

nvd nist
Published: Sep 17, 2024Modified: Sep 23, 2024

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

Contao is an Open Source CMS. In affected versions an untrusted user can inject insert tags into the canonical tag, which are then replaced on the web page (front end). Users are advised to update to Contao 4.13.49, 5.3.15 or 5.4.3. Users unable to upgrade should disable canonical tags in the root page settings.

Affected (3)

Products: Contao: Contao
1 product
Contao
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Contao
From 4.13.0 to 4.13.49
From 5.3.0 to 5.3.15
From 5.4.0 to 5.4.3

References (2)

Source: security-advisories@github.com
Vendor Advisory

Timeline

No history available yet.