MEDIUM4.6
GHSA-5wx6-xwxf-q8qj
Cross-Site Scripting in TYPO3 Backend
Quick fix
GHSA-5wx6-xwxf-q8qj — typo3/cms: upgrade to the fixed version with the command below.
composer require typo3/cms:^6.2.20Details
Failing to properly encode user input, some backend components are vulnerable to Cross-Site Scripting. A valid backend user account is needed to exploit this vulnerability.
Are you affected?
Enter the version of the package you're using.