Логотип exploitDog
bind:CVE-2024-34357
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-34357

Количество 2

Количество 2

nvd логотип

CVE-2024-34357

больше 1 года назад

TYPO3 is an enterprise content management system. Starting in version 9.0.0 and prior to versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, and 13.1.1, failing to properly encode user-controlled values in file entities, the `ShowImageController` (`_eID tx_cms_showpic_`) is vulnerable to cross-site scripting. Exploiting this vulnerability requires a valid backend user account with access to file entities. TYPO3 versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, 13.1.1 fix the problem described.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-hw6c-6gwq-3m3m

больше 1 года назад

TYPO3 vulnerable to Cross-Site Scripting in the ShowImageController

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-34357

TYPO3 is an enterprise content management system. Starting in version 9.0.0 and prior to versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, and 13.1.1, failing to properly encode user-controlled values in file entities, the `ShowImageController` (`_eID tx_cms_showpic_`) is vulnerable to cross-site scripting. Exploiting this vulnerability requires a valid backend user account with access to file entities. TYPO3 versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, 13.1.1 fix the problem described.

CVSS3: 5.4
1%
Низкий
больше 1 года назад
github логотип
GHSA-hw6c-6gwq-3m3m

TYPO3 vulnerable to Cross-Site Scripting in the ShowImageController

CVSS3: 5.4
1%
Низкий
больше 1 года назад

Уязвимостей на страницу