Lucene search

K
cvelistGitHub_MCVELIST:CVE-2022-24899
HistoryMay 05, 2022 - 11:45 p.m.

CVE-2022-24899 Cross site scripting via canonical tag

2022-05-0523:45:13
CWE-79
GitHub_M
www.cve.org

7.2 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

0.003 Low

EPSS

Percentile

71.6%

Contao is a powerful open source CMS that allows you to create professional websites and scalable web applications. In versions of Contao prior to 4.13.3 it is possible to inject code into the canonical tag. As a workaround users may disable canonical tags in the root page settings.

CNA Affected

[
  {
    "product": "contao",
    "vendor": "contao",
    "versions": [
      {
        "status": "affected",
        "version": "< 4.13.3"
      }
    ]
  }
]

7.2 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

0.003 Low

EPSS

Percentile

71.6%