MEDIUM4.6
GHSA-86r8-4g3w-7xjp
Cross-Site Scripting in TYPO3 Backend
Quick fix
GHSA-86r8-4g3w-7xjp — typo3/cms: upgrade to the fixed version with the command below.
composer require typo3/cms:^6.2.26Details
Failing to properly encode user input, some backend components are vulnerable to Cross-Site Scripting. A valid backend user account is needed to exploit this vulnerability.
Are you affected?
Enter the version of the package you're using.