Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m8x6-6r63-qvj2

Опубликовано: 20 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.2

Описание

Cross site scripting via canonical tag in Contao

Impact

Untrusted users can inject malicious code into the canonical tag, which is then executed on the web page (front end).

Patches

Update to Contao 4.13.3.

Workarounds

Disable canonical tags in the root page settings.

References

https://contao.org/en/security-advisories/cross-site-scripting-via-canonical-url

For more information

If you have any questions or comments about this advisory, open an issue in contao/contao.

Пакеты

Наименование

contao/core-bundle

composer
Затронутые версииВерсия исправления

>= 4.13.0, < 4.13.3

4.13.3

Наименование

contao/contao

composer
Затронутые версииВерсия исправления

>= 4.13.0, < 4.13.3

4.13.3

EPSS

Процентиль: 98%
0.59505
Средний

7.2 High

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 7.2
nvd
почти 4 года назад

Contao is a powerful open source CMS that allows you to create professional websites and scalable web applications. In versions of Contao prior to 4.13.3 it is possible to inject code into the canonical tag. As a workaround users may disable canonical tags in the root page settings.

EPSS

Процентиль: 98%
0.59505
Средний

7.2 High

CVSS3

Дефекты

CWE-79