S4E just found a high top 10 tcp port service scan
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-24899 Scanner

Detects 'Cross-Site Scripting (XSS)' vulnerability in Contao affects v. prior to 4.13.3.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-24899
6.1
CVSShigh
Exploitable remotely over the internet · no authentication required.

Contao is a powerful open source CMS that allows you to create professional websites and scalable web applications. In versions of Contao prior to 4.13.3 it is possible to inject code into the canonical tag. As a workaround users may disable canonical tags in the root page settings.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
contaoby contao
< 4.13.3
Updated Aug 22, 2026View on NVD →
Detail

Contao is a widely used open source CMS that empowers users to develop professional websites and scalable web applications. The platform is equipped with an extensive set of features that make it an ideal choice for businesses, organizations, and individuals seeking to build and manage digital assets without incurring prohibitive expenses.

The CVE-2022-24899 vulnerability recently detected in Contao prior to version 4.13.3 could expose users to significant cybersecurity risks. The flaw allows attackers to inject code into the canonical tag, causing issues with page indexing, link equity, and user experience. This vulnerability may also enable hackers to launch arbitrary code execution attacks, which could result in data theft, system hijacking, and other forms of digital threats.

If exploited, the CVE-2022-24899 vulnerability can lead to various adverse consequences such as unauthorized access to sensitive data and systems, malware infections, and website defacements. This could result in loss of reputation, revenue, customers, and even legal liability. Moreover, the impact of such cyber attacks can be long-lasting and difficult to reverse.

In conclusion, Contao is a powerful CMS that offers users numerous benefits, including flexibility, ease of use, and customization. However, the CVE-2022-24899 vulnerability detected in earlier versions of Contao highlights the need for vigilance and proactive measures to mitigate cybersecurity risks. By leveraging the pro features of the s4e.io platform, users can stay informed about the latest vulnerabilities in their digital assets and take appropriate actions to safeguard their systems and data.

 

REFERENCES

Solution Advice

To protect against the CVE-2022-24899 vulnerability, users of Contao should take the following precautions:

  • Upgrade their installation to the latest version of Contao (4.13.3 or later).
  • Disable the canonical tags in the root page settings as a workaround until the upgrade is completed.
  • Implement access control policies and user authentication methods to restrict unauthorized access to the system.
  • Use a web application firewall (WAF) to monitor and filter incoming traffic for potential threats.
  • Conduct regular vulnerability assessments and penetration testing to identify and remediate any security issues proactively.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2022-24899 scanner - Cross-Site Scripting (XSS) vulnerability in Contao S4E