MEDIUM5.4
GHSA-gg48-mpp8-cgqc
ke_search for Typo3 XSS Vulnerability
Quick fix
GHSA-gg48-mpp8-cgqc — tpwd/ke_search: upgrade to the fixed version with the command below.
composer require tpwd/ke_search:^3.1.4Details
The ke_search (aka Faceted Search) extension through 2.8.2, and 3.x through 3.1.3, for TYPO3 allows XSS.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/tpwd/ke_search
Introduced in:
3.0.0Fixed in: 3.1.4Fix
composer require tpwd/ke_search:^3.1.4References
- https://nvd.nist.gov/vuln/detail/CVE-2020-15517[ADVISORY]
- https://github.com/tpwd/ke_search/commit/1cde32c3ebfcb6cda5d364f099979be9741f6714[WEB]
- https://github.com/tpwd/ke_search/commit/9551aa4eef441a3e9825776d4a19ee4b6fe6f8ea[WEB]
- https://github.com/tpwd/ke_search[PACKAGE]
- https://typo3.org/security/advisory/typo3-ext-sa-2020-009[WEB]