VDB
Sign up
MEDIUM5.4

GHSA-4j77-gg36-9864

Cross-Site Scripting in TYPO3 CMS Link Handling

Quick fix

GHSA-4j77-gg36-9864 — typo3/cms-core: upgrade to the fixed version with the command below.

composer require typo3/cms-core:^10.4.2

Details

It has been discovered that link tags generated by `typolink` functionality are vulnerable to cross-site scripting - properties being assigned as HTML attributes have not been parsed correctly.

Update to TYPO3 versions 9.5.17 or 10.4.2 that fix the problem described.

### References * https://typo3.org/security/advisory/typo3-core-sa-2020-003

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/typo3/cms-core
Introduced in: 10.0.0Fixed in: 10.4.2
Fixcomposer require typo3/cms-core:^10.4.2
Packagist/typo3/cms-core
Introduced in: 9.0.0Fixed in: 9.5.17
Fixcomposer require typo3/cms-core:^9.5.17
Packagist/typo3/cms
Introduced in: 10.0.0Fixed in: 10.4.2
Fixcomposer require typo3/cms:^10.4.2
Packagist/typo3/cms
Introduced in: 9.0.0Fixed in: 9.5.17
Fixcomposer require typo3/cms:^9.5.17

References