VDB
Sign up
MEDIUM5.4

GHSA-29wr-24h5-95r5

Typo3 XSS Vulnerability

Quick fix

GHSA-29wr-24h5-95r5 — typo3/cms: upgrade to the fixed version with the command below.

composer require typo3/cms:^4.5.4

Details

Cross-site Scripting (XSS) in TYPO3 before 4.3.12, 4.4.x before 4.4.9, and 4.5.x before 4.5.4 allows remote attackers to inject arbitrary web script or HTML via the `browse_links` wizard.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/typo3/cms
Introduced in: 4.5.0Fixed in: 4.5.4
Fixcomposer require typo3/cms:^4.5.4
Packagist/typo3/cms
Introduced in: 4.4.0Fixed in: 4.4.9
Fixcomposer require typo3/cms:^4.4.9
Packagist/typo3/cms
Introduced in: 0Fixed in: 4.3.12
Fixcomposer require typo3/cms:^4.3.12

References