MEDIUM6.3
GHSA-f4m6-x2xj-jc7w
ke_search (aka Faceted Search) vulnerable to Cross-Site Scripting
Quick fix
GHSA-f4m6-x2xj-jc7w — tpwd/ke_search: upgrade to the fixed version with the command below.
composer require tpwd/ke_search:^5.0.2Details
The ke_search (aka Faceted Search) extension before 4.0.3, 4.1.x through 4.6.x before 4.6.6, and 5.x before 5.0.2 for TYPO3 allows XSS via indexed data.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/tpwd/ke_search
Introduced in:
5.0.0Fixed in: 5.0.2Fix
composer require tpwd/ke_search:^5.0.2Packagist/tpwd/ke_search
Introduced in:
4.1.0Fixed in: 4.6.6Fix
composer require tpwd/ke_search:^4.6.6References
- https://nvd.nist.gov/vuln/detail/CVE-2023-35783[ADVISORY]
- https://github.com/tpwd/ke_search/commit/14fa0703c2469e04eb398be4ae6268ec6ad6e720[WEB]
- https://github.com/tpwd/ke_search/commit/b0f05d7e7e207bc0d5051bd96f3ff43c5c3658c6[WEB]
- https://github.com/tpwd/ke_search/commit/d81a1f2f3dcb612220d505b495bc2851b87f6f74[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/tpwd/ke_search/CVE-2023-35783.yaml[WEB]
- https://github.com/tpwd/ke_search[PACKAGE]
- https://typo3.org/security/advisory/typo3-ext-sa-2023-004[WEB]