The Wayback Machine - https://web.archive.org/web/20200526040450/https://github.com/advisories/GHSA-43gj-mj2w-wh46
Skip to content

Cross-Site Scripting in TYPO3 CMS Form Engine

moderate severity CVE-2020-11064 published May 13, 2020 • updated May 13, 2020
Repository
@TYPO3 TYPO3/TYPO3.CMS
Packages Affected versions Patched versions
typo3/cms-core (composer) >= 9.0.0, < 9.5.17 9.5.17
>= 10.0.0, < 10.4.2 10.4.2

In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.17 and greater than or equal to 10.0.0 and less than 10.4.2, it has been discovered that HTML placeholder attributes containing data of other database records are vulnerable to cross-site scripting. A valid backend user account is needed to exploit this vulnerability.

Update to TYPO3 versions 9.5.17 or 10.4.2 that fix the problem described.

References

References

@ohader ohader published the maintainer security advisory May 12, 2020
You can’t perform that action at this time.