Medium severity5.3NVD Advisory· Published Sep 17, 2024· Updated Jun 17, 2026
CVE-2024-45612
CVE-2024-45612
Description
Contao is an Open Source CMS. In affected versions an untrusted user can inject insert tags into the canonical tag, which are then replaced on the web page (front end). Users are advised to update to Contao 4.13.49, 5.3.15 or 5.4.3. Users unable to upgrade should disable canonical tags in the root page settings.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
contao/core-bundlePackagist | >= 4.13.0, < 4.13.49 | 4.13.49 |
contao/core-bundlePackagist | >= 5.0.0, < 5.3.15 | 5.3.15 |
contao/core-bundlePackagist | >= 5.4.0, < 5.4.3 | 5.4.3 |
Affected products
3Patches
Vulnerability mechanics
References
7- contao.org/en/security-advisories/insert-tag-injection-via-canonical-urlsnvdVendor AdvisoryWEB
- github.com/advisories/GHSA-2xpq-xp6c-5mgjghsaADVISORY
- github.com/contao/contao/security/advisories/GHSA-2xpq-xp6c-5mgjnvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2024-45612ghsaADVISORY
- github.com/contao/contao/commit/1c28e9ac7a7b915134962a59681a8701a44ccbe2ghsaWEB
- github.com/contao/contao/commit/d105224e14ddc84f27cd8802b553369decdcbe66ghsaWEB
- github.com/contao/contao/commit/ffe05cda5310dc2bd259d1391197f3849dab8590ghsaWEB
News mentions
0No linked articles in our index yet.