Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-38500

Опубликовано: 25 июл. 2023
Источник: nvd
CVSS3: 4.7
CVSS3: 6.1
EPSS Низкий

Описание

TYPO3 HTML Sanitizer is an HTML sanitizer, written in PHP, aiming to provide cross-site-scripting-safe markup based on explicitly allowed tags, attributes and values. Starting in version 1.0.0 and prior to versions 1.5.1 and 2.1.2, due to an encoding issue in the serialization layer, malicious markup nested in a noscript element was not encoded correctly. noscript is disabled in the default configuration, but might have been enabled in custom scenarios. This allows bypassing the cross-site scripting mechanism of TYPO3 HTML Sanitizer. Versions 1.5.1 and 2.1.2 fix the problem.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:typo3:html_sanitizer:*:*:*:*:*:*:*:*
Версия от 1.0.0 (включая) до 1.5.1 (исключая)
cpe:2.3:a:typo3:html_sanitizer:*:*:*:*:*:*:*:*
Версия от 2.0.0 (включая) до 2.1.2 (исключая)

EPSS

Процентиль: 56%
0.00341
Низкий

4.7 Medium

CVSS3

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 4.7
ubuntu
больше 2 лет назад

TYPO3 HTML Sanitizer is an HTML sanitizer, written in PHP, aiming to provide cross-site-scripting-safe markup based on explicitly allowed tags, attributes and values. Starting in version 1.0.0 and prior to versions 1.5.1 and 2.1.2, due to an encoding issue in the serialization layer, malicious markup nested in a `noscript` element was not encoded correctly. `noscript` is disabled in the default configuration, but might have been enabled in custom scenarios. This allows bypassing the cross-site scripting mechanism of TYPO3 HTML Sanitizer. Versions 1.5.1 and 2.1.2 fix the problem.

CVSS3: 4.7
github
больше 2 лет назад

By-passing Cross-Site Scripting Protection in HTML Sanitizer

EPSS

Процентиль: 56%
0.00341
Низкий

4.7 Medium

CVSS3

6.1 Medium

CVSS3

Дефекты

CWE-79