Описание
Cross-Site Scripting in Query Generator & Query View
Meta
- CVSS:
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N/E:F/RL:O/RC:C(4.5)
Problem
Failing to properly encode error messages, the components QueryGenerator and QueryView are vulnerable to both reflected and persistent cross-site scripting. A valid backend user account having administrator privileges is needed to exploit this vulnerability.
Solution
Update to TYPO3 versions 8.7.41 ELTS, 9.5.28, 10.4.18, 11.3.1 that fix the problem described.
Credits
Thanks to Richie Lee who reported this issue and to TYPO3 security team member Oliver Hader who fixed the issue.
References
Ссылки
- https://github.com/TYPO3/TYPO3.CMS/security/advisories/GHSA-6mh3-j5r5-2379
- https://github.com/TYPO3/typo3/security/advisories/GHSA-6mh3-j5r5-2379
- https://nvd.nist.gov/vuln/detail/CVE-2021-32668
- https://github.com/FriendsOfPHP/security-advisories/blob/master/typo3/cms-core/CVE-2021-32668.yaml
- https://github.com/FriendsOfPHP/security-advisories/blob/master/typo3/cms/CVE-2021-32668.yaml
- https://typo3.org/security/advisory/typo3-core-sa-2021-010
Пакеты
typo3/cms-core
>= 8.0.0, < 8.7.41
8.7.41
typo3/cms-core
>= 9.0.0, < 9.5.28
9.5.28
typo3/cms-core
>= 10.0.0, < 10.4.18
10.4.18
typo3/cms-core
>= 11.0.0, < 11.3.1
11.3.1
typo3/cms
>= 10.0.0, < 10.4.18
10.4.18
typo3/cms
>= 11.0.0, < 11.3.1
11.3.1
typo3/cms
>= 9.0.0, < 9.5.28
9.5.28
Связанные уязвимости
TYPO3 is an open source PHP based web content management system. Versions 9.0.0 through 9.5.28, 10.0.0 through 10.4.17, and 11.0.0 through 11.3.0 have a cross-site scripting vulnerability. When error messages are not properly encoded, the components _QueryGenerator_ and _QueryView_ are vulnerable to both reflected and persistent cross-site scripting. A valid backend user account having administrator privileges is needed to exploit this vulnerability. TYPO3 versions 9.5.29, 10.4.18, 11.3.1 contain a patch for this issue.
Уязвимость компонентов Query Generator и Query View системы управления контентом TYPO3, позволяющая нарушителю осуществлять межсайтовые сценарные атаки