{"id":"CVE-2022-24899","aliases":["GHSA-m8x6-6r63-qvj2"],"url":"https://o3.security/vulnerability/CVE-2022-24899","summary":"Cross site scripting via canonical tag","details":"### Impact\n\nUntrusted users can inject malicious code into the canonical tag, which is then executed on the web page (front end).\n\n### Patches\n\nUpdate to Contao 4.13.3.\n\n### Workarounds\n\nDisable canonical tags in the root page settings.\n\n### References\n\nhttps://contao.org/en/security-advisories/cross-site-scripting-via-canonical-url\n\n### For more information\n\nIf you have any questions or comments about this advisory, open an issue in [contao/contao](https://github.com/contao/contao/issues/new/choose).","published":"2022-05-05T23:45:13Z","modified":"2026-08-12T03:51:32.190868545Z","cvss":{"score":7.2,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"},"epss":{"score":0.04478,"percentile":0.90761,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"contao/core-bundle","fixedVersion":"4.13.3"},{"ecosystem":"Packagist","name":"contao/contao","fixedVersion":"4.13.3"}],"fix":{"url":"https://github.com/contao/contao/commit/199206849a87ddd0fa5cf674eb3c58292fd8366c","label":"contao/contao@1992068"},"references":[{"type":"ADVISORY","url":"https://contao.org/en/security-advisories/cross-site-scripting-via-canonical-url.html"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/24xxx/CVE-2022-24899.json"},{"type":"ADVISORY","url":"https://github.com/contao/contao/security/advisories/GHSA-m8x6-6r63-qvj2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-24899"},{"type":"FIX","url":"https://github.com/contao/contao/commit/199206849a87ddd0fa5cf674eb3c58292fd8366c"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/contao/contao/CVE-2022-24899.yaml"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/contao/core-bundle/CVE-2022-24899.yaml"},{"type":"PACKAGE","url":"https://github.com/contao/contao"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:32.190868545Z"}}