Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h4mx-xv96-2jgm

Опубликовано: 17 июн. 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.4

Описание

Cross-Site Scripting in TYPO3's Frontend Login Mailer

Meta

  • CVSS: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N/E:F/RL:O/RC:C (4.9)

Problem

User submitted content was used without being properly encoded in HTML emails sent to users. The actually affected components were mail clients used to view those messages.

Solution

Update to TYPO3 versions 9.5.35 ELTS, 10.4.29, 11.5.11 that fix the problem described above.

Credits

Thanks to Christian Seifert who reported this issue and to TYPO3 framework merger Andreas Fernandez who fixed the issue.

References

Пакеты

Наименование

typo3/cms-core

composer
Затронутые версииВерсия исправления

>= 9.0.0, < 9.5.35

9.5.35

Наименование

typo3/cms-core

composer
Затронутые версииВерсия исправления

>= 10.0.0, < 10.4.29

10.4.29

Наименование

typo3/cms-core

composer
Затронутые версииВерсия исправления

>= 11.0.0, < 11.5.11

11.5.11

Наименование

typo3/cms

composer
Затронутые версииВерсия исправления

>= 10.0.0, < 10.4.29

10.4.29

Наименование

typo3/cms

composer
Затронутые версииВерсия исправления

>= 11.0.0, < 11.5.11

11.5.11

EPSS

Процентиль: 70%
0.0063
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
больше 3 лет назад

TYPO3 is an open source web content management system. Prior to versions 9.5.34 ELTS, 10.4.29, and 11.5.11, user submitted content was used without being properly encoded in HTML emails sent to users. The actually affected components were mail clients used to view those messages. TYPO3 versions 9.5.34 ELTS, 10.4.29, and 11.5.11 contain a fix for the problem.

EPSS

Процентиль: 70%
0.0063
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79