We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Untrusted users can inject malicious code into the canonical tag, which is then executed on the web page (front end).
Update to Contao 4.13.3.
Disable canonical tags in the root page settings.
https://contao.org/en/security-advisories/cross-site-scripting-via-canonical-url
If you have any questions or comments about this advisory, open an issue in contao/contao.
Impact
Untrusted users can inject malicious code into the canonical tag, which is then executed on the web page (front end).
Patches
Update to Contao 4.13.3.
Workarounds
Disable canonical tags in the root page settings.
References
https://contao.org/en/security-advisories/cross-site-scripting-via-canonical-url
For more information
If you have any questions or comments about this advisory, open an issue in contao/contao.