VDB
Sign up
LOW

GHSA-jvf5-rxvv-3mcg

TYPO3 HTML Sanitizer allows Cross-site Scripting

Quick fix

GHSA-jvf5-rxvv-3mcg — typo3/html-sanitizer: upgrade to the fixed version with the command below.

composer require typo3/html-sanitizer:^2.3.2

Details

When `ALLOW_INSECURE_RAW_TEXT` is enabled, whitespace-variant closing tags (e.g., `</style\\t>`) are not recognized by the sanitizer but accepted by browsers as valid end tags, allowing subsequent content to escape sanitization. This allows bypassing the cross-site scripting prevention mechanism of `typo3/html-sanitizer` before version 2.3.2.

Credits to IPC Labs for reporting this vulnerability.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/typo3/html-sanitizer
Introduced in: 0Fixed in: 2.3.2
Fixcomposer require typo3/html-sanitizer:^2.3.2

References