THREATINT

We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Fathom (Privacy friendly web analytics)
Zendesk (Helpdesk and Chat)

Ok

Home | EN
Support
CVE
PUBLISHED

CVE-2024-34356

TYPO3 vulnerable to Cross-Site Scripting in the Form Manager Module

AssignerGitHub_M
Reserved2024-05-02
Published2024-05-14
Updated2024-06-04

Description

TYPO3 is an enterprise content management system. Starting in version 9.0.0 and prior to versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, and 13.1.1, the form manager backend module is vulnerable to cross-site scripting. Exploiting this vulnerability requires a valid backend user account with access to the form module. TYPO3 versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, and 13.1.1 fix the problem described.



MEDIUM: 5.4CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Problem types

CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Product status

>= 9.0.0, < 9.5.48
affected

>= 10.0.0, < 10.4.45
affected

>= 11.0.0, < 11.5.37
affected

>= 12.0.0, < 12.4.15
affected

>= 13.0.0, < 13.1.1
affected

References

https://github.com/TYPO3/typo3/security/advisories/GHSA-v6mw-h7w6-59w3

https://github.com/TYPO3/typo3/commit/2832e2f51f929aeddb5de7d667538a33ceda8156

https://github.com/TYPO3/typo3/commit/d0393a879a32fb4e3569acad6bdb5cda776be1e5

https://github.com/TYPO3/typo3/commit/e95a1224719efafb9cab2d85964f240fd0356e64

https://typo3.org/security/advisory/typo3-core-sa-2024-008

cve.org CVE-2024-34356

nvd.nist.gov CVE-2024-34356

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2024-34356
© Copyright 2024 THREATINT. Made in Cyprus with +