MEDIUM
GHSA-6fc6-cj2j-h22x
TYPO3 Multiple Cross-Site Scripting vulnerabilities in frontend
Quick fix
GHSA-6fc6-cj2j-h22x — typo3/cms: upgrade to the fixed version with the command below.
composer require typo3/cms:^6.2.16Details
Failing to properly encode editor input, several frontend components are susceptible to Cross-Site Scripting, allowing authenticated editors to inject arbitrary HTML.
Are you affected?
Enter the version of the package you're using.