Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-75mx-chcf-2q32

Опубликовано: 30 мая 2024
Источник: github
Github: Прошло ревью
CVSS3: 6.1

Описание

Duplicate Advisory: TYPO3 Cross-Site Scripting vulnerability in typolinks

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-j5v7-9xr5-m7gx. This link is maintained to preserve external references.

Original Description

All link fields within the TYPO3 installation are vulnerable to Cross-Site Scripting as authorized editors can insert javascript commands by using the url scheme javascript:.

Пакеты

Наименование

typo3/cms

composer
Затронутые версииВерсия исправления

>= 6.2.0, < 6.2.16

6.2.16

Наименование

typo3/cms

composer
Затронутые версииВерсия исправления

>= 7.0.0, < 7.6.1

7.6.1

6.1 Medium

CVSS3

Дефекты

CWE-79

6.1 Medium

CVSS3

Дефекты

CWE-79