MEDIUM
GHSA-8j9v-4hhh-x43c
Cross-Site Scripting (XSS) in TYPO3 component CSS styled content
Quick fix
GHSA-8j9v-4hhh-x43c — typo3/cms: upgrade to the fixed version with the command below.
composer require typo3/cms:^6.2.19Details
Failing to properly encode user input, the CSS styled content component is susceptible to Cross-Site Scripting, allowing authenticated editors to inject arbitrary HTML or JavaScript.
Are you affected?
Enter the version of the package you're using.