Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWZqaDMtZzhncS05cTky

Cross-Site Scripting in Content Preview

Meta

  • CVSS: AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N/E:F/RL:O/RC:C (5.0)
  • CWE-79
  • Status: DRAFT

Problem

It has been discovered that database fields used as descriptionColumn are vulnerable to cross-site scripting when their content gets previewed in the page module. A valid backend user account is needed to exploit this vulnerability.

Solution

Update to TYPO3 versions 10.4.14, 11.1.1 that fix the problem described.

Credits

Thanks to Richie Lee who reported this issue and to TYPO3 framework merger Andreas Fernandez who fixed the issue.

References

Permalink: https://github.com/advisories/GHSA-fjh3-g8gq-9q92
JSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWZqaDMtZzhncS05cTky
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Low
Classification: General
Published: over 2 years ago
Updated: 8 months ago


Identifiers: GHSA-fjh3-g8gq-9q92, CVE-2021-21340
References:

Affected Packages

packagist:typo3/cms-backend
Versions: >= 11.0.0, <= 11.1.0, >= 10.0.0, <= 10.4.13
Fixed in: 11.1.1, 10.4.14