Описание
Cross-Site Scripting in third party library mso/idna-convert
Make sure to not expose the vendor directory to the publicly accessible document root. In composer managed installation, make sure to configure a dedicated web folder. In general it is recommended to not expose the complete typo3_src sources folder in the document root.
Пакеты
Наименование
typo3/cms
composer
Затронутые версииВерсия исправления
>= 7.6.0, < 7.6.10
7.6.10
Наименование
typo3/cms
composer
Затронутые версииВерсия исправления
>= 8.0.0, < 8.2.1
8.2.1
Дефекты
CWE-79
Дефекты
CWE-79