Описание
Cross-Site Scripting in TYPO3 CMS Backend
Failing to properly encode user input, backend forms are vulnerable to Cross-Site Scripting. A valid backend user account is needed to exploit this vulnerability.
Пакеты
Наименование
typo3/cms
composer
Затронутые версииВерсия исправления
>= 8.0.0, < 8.7.5
8.7.5
5.4 Medium
CVSS3
Дефекты
CWE-79
5.4 Medium
CVSS3
Дефекты
CWE-79