MEDIUM5.4
GHSA-7q33-hxwj-7p8v
TYPO3 Cross-Site Scripting in Backend Modal Component
Quick fix
GHSA-7q33-hxwj-7p8v — typo3/cms: upgrade to the fixed version with the command below.
composer require typo3/cms:^7.6.32Details
Failing to properly encode user input, notifications shown in modal windows in the TYPO3 backend are vulnerable to cross-site scripting. A valid backend user account is needed in order to exploit this vulnerability.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/TYPO3/typo3/commit/02cd5c97228cba477d16c68e28309ce25c433ce9[WEB]
- https://github.com/TYPO3/typo3/commit/89a38ad0ef9411745954f53f29bea5b8ce81cd32[WEB]
- https://github.com/TYPO3/typo3/commit/c35646c3f7795a4a7b0046a88f146b490fa4883c[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/typo3/cms/2018-12-11-2.yaml[WEB]
- https://github.com/TYPO3/typo3[PACKAGE]
- https://typo3.org/security/advisory/typo3-core-sa-2018-007[WEB]