Cross site scripting via canonical tag in Contao
Description
Published by the National Vulnerability Database
May 6, 2022
Published to the GitHub Advisory Database
May 20, 2022
Reviewed
May 20, 2022
Last updated
Apr 22, 2024
Impact
Untrusted users can inject malicious code into the canonical tag, which is then executed on the web page (front end).
Patches
Update to Contao 4.13.3.
Workarounds
Disable canonical tags in the root page settings.
References
https://contao.org/en/security-advisories/cross-site-scripting-via-canonical-url
For more information
If you have any questions or comments about this advisory, open an issue in contao/contao.
References