VDB
Sign up
MEDIUM

GHSA-c73w-4rcj-2622

Typo3 API Install Tool vulnerable to Cross-site Scripting

Quick fix

GHSA-c73w-4rcj-2622 — typo3/cms-install: upgrade to the fixed version with the command below.

composer require typo3/cms-install:^4.1.13

Details

Cross-site scripting (XSS) vulnerability in the Install Tool subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/typo3/cms-install
Introduced in: 0

No fixed version published yet for typo3/cms-install (composer). Pin to a known-safe version or switch to an alternative.

Packagist/typo3/cms-install
Introduced in: 4.1.0Fixed in: 4.1.13
Fixcomposer require typo3/cms-install:^4.1.13
Packagist/typo3/cms-install
Introduced in: 4.2.0Fixed in: 4.2.10
Fixcomposer require typo3/cms-install:^4.2.10
Packagist/typo3/cms-install
Introduced in: 4.3alpha1Fixed in: 4.3beta2
Fixcomposer require typo3/cms-install:^4.3beta2

References