MEDIUM
GHSA-c73w-4rcj-2622
Typo3 API Install Tool vulnerable to Cross-site Scripting
Quick fix
GHSA-c73w-4rcj-2622 — typo3/cms-install: upgrade to the fixed version with the command below.
composer require typo3/cms-install:^4.1.13Details
Cross-site scripting (XSS) vulnerability in the Install Tool subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/typo3/cms-install
Introduced in:
0No fixed version published yet for typo3/cms-install (composer). Pin to a known-safe version or switch to an alternative.
Packagist/typo3/cms-install
Introduced in:
4.1.0Fixed in: 4.1.13Fix
composer require typo3/cms-install:^4.1.13Packagist/typo3/cms-install
Introduced in:
4.2.0Fixed in: 4.2.10Fix
composer require typo3/cms-install:^4.2.10Packagist/typo3/cms-install
Introduced in:
4.3alpha1Fixed in: 4.3beta2Fix
composer require typo3/cms-install:^4.3beta2References
- https://nvd.nist.gov/vuln/detail/CVE-2009-3636[ADVISORY]
- https://exchange.xforce.ibmcloud.com/vulnerabilities/53929[WEB]
- https://github.com/TYPO3-CMS/install[PACKAGE]
- https://web.archive.org/web/20101223093042/http://www.securityfocus.com/bid/36801[WEB]
- http://marc.info/?l=oss-security&m=125632856206736&w=2[WEB]
- http://marc.info/?l=oss-security&m=125633199111438&w=2[WEB]
- http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-016[WEB]