Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xjwx-78x7-q6jc

Опубликовано: 14 мая 2024
Источник: github
Github: Прошло ревью
CVSS3: 3.5

Описание

TYPO3 vulnerable to an HTML Injection in the History Module

Problem

The history backend module is vulnerable to HTML injection. Although Content-Security-Policy headers effectively prevent JavaScript execution, adversaries can still inject malicious HTML markup. Exploiting this vulnerability requires a valid backend user account.

Solution

Update to TYPO3 version 13.1.1 that fixes the problem described.

Credits

Thanks to TYPO3 core team member Andreas Kienast who reported this issue and to TYPO3 core & security team Benjamin Franzke who fixed the issue.

References

Пакеты

Наименование

typo3/cms-core

composer
Затронутые версииВерсия исправления

>= 13.0.0, <= 13.1.0

13.1.1

EPSS

Процентиль: 69%
0.00615
Низкий

3.5 Low

CVSS3

Дефекты

CWE-116
CWE-79

Связанные уязвимости

CVSS3: 3.5
nvd
больше 1 года назад

TYPO3 is an enterprise content management system. Starting in version 13.0.0 and prior to version 13.1.1, the history backend module is vulnerable to HTML injection. Although Content-Security-Policy headers effectively prevent JavaScript execution, adversaries can still inject malicious HTML markup. Exploiting this vulnerability requires a valid backend user account. TYPO3 version 13.1.1 fixes the problem described.

EPSS

Процентиль: 69%
0.00615
Низкий

3.5 Low

CVSS3

Дефекты

CWE-116
CWE-79