THREATINT

We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Fathom (Privacy friendly web analytics)
Zendesk (Helpdesk and Chat)

Ok

Home | EN
Support
CVE
PUBLISHED

CVE-2024-34357

TYPO3 vulnerable to Cross-Site Scripting in ShowImageController

AssignerGitHub_M
Reserved2024-05-02
Published2024-05-14
Updated2024-06-12

Description

TYPO3 is an enterprise content management system. Starting in version 9.0.0 and prior to versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, and 13.1.1, failing to properly encode user-controlled values in file entities, the `ShowImageController` (`_eID tx_cms_showpic_`) is vulnerable to cross-site scripting. Exploiting this vulnerability requires a valid backend user account with access to file entities. TYPO3 versions 9.5.48 ELTS, 10.4.45 ELTS, 11.5.37 LTS, 12.4.15 LTS, 13.1.1 fix the problem described.



MEDIUM: 5.4CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Problem types

CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Product status

>= 9.0.0, < 9.5.48
affected

>= 10.0.0, < 10.4.45
affected

>= 11.0.0, < 11.5.37
affected

>= 12.0.0, < 12.4.15
affected

>= 13.0.0, < 13.1.1
affected

References

https://github.com/TYPO3/typo3/security/advisories/GHSA-hw6c-6gwq-3m3m

https://github.com/TYPO3/typo3/commit/376474904f6b9a54dc1b785a2e45277cbd13b0d7

https://github.com/TYPO3/typo3/commit/b31d05d1da3eeaeead2d19eb43b1c3f9c88e15ee

https://github.com/TYPO3/typo3/commit/d774642381354d3bf5095a5a26e18acd2767f0b1

https://typo3.org/security/advisory/typo3-core-sa-2024-009

cve.org CVE-2024-34357

nvd.nist.gov CVE-2024-34357

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2024-34357
© Copyright 2024 THREATINT. Made in Cyprus with +