Описание
Cross site scripting via canonical tag in Contao
Impact
Untrusted users can inject malicious code into the canonical tag, which is then executed on the web page (front end).
Patches
Update to Contao 4.13.3.
Workarounds
Disable canonical tags in the root page settings.
References
https://contao.org/en/security-advisories/cross-site-scripting-via-canonical-url
For more information
If you have any questions or comments about this advisory, open an issue in contao/contao.
Ссылки
- https://github.com/contao/contao/security/advisories/GHSA-m8x6-6r63-qvj2
- https://nvd.nist.gov/vuln/detail/CVE-2022-24899
- https://github.com/contao/contao/commit/199206849a87ddd0fa5cf674eb3c58292fd8366c
- https://contao.org/en/security-advisories/cross-site-scripting-via-canonical-url.html
- https://github.com/FriendsOfPHP/security-advisories/blob/master/contao/contao/CVE-2022-24899.yaml
- https://github.com/FriendsOfPHP/security-advisories/blob/master/contao/core-bundle/CVE-2022-24899.yaml
Пакеты
contao/core-bundle
>= 4.13.0, < 4.13.3
4.13.3
contao/contao
>= 4.13.0, < 4.13.3
4.13.3
Связанные уязвимости
Contao is a powerful open source CMS that allows you to create professional websites and scalable web applications. In versions of Contao prior to 4.13.3 it is possible to inject code into the canonical tag. As a workaround users may disable canonical tags in the root page settings.