GHSA-mm79-jhqm-9j54
Bypassing Cross-Site Scripting Protection in TYPO3 HTML Sanitizer
Quick fix
GHSA-mm79-jhqm-9j54 — typo3/html-sanitizer: upgrade to the fixed version with the command below.
composer require typo3/html-sanitizer:^1.5.3Details
> ### CVSS: `CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N/E:F/RL:O/RC:C` (4.4)
### Problem DOM processing instructions are not handled correctly. This allows bypassing the cross-site scripting mechanism of [`typo3/html-sanitizer`](https://packagist.org/packages/typo3/html-sanitizer).
### Solution Update to `typo3/html-sanitizer` versions 1.5.3 or 2.1.4 that fix the problem described.
### Credits Thanks to Yaniv Nizry and Niels Dossche who reported this issue, and to TYPO3 core & security team member Oliver Hader who fixed the issue.
### References * [TYPO3-CORE-SA-2023-007](https://typo3.org/security/advisory/typo3-core-sa-2023-007) * [Context & Details at `masterminds/html5`](https://github.com/Masterminds/html5-php/issues/241)
Are you affected?
Enter the version of the package you're using.
Affected packages
1.0.0Fixed in: 1.5.3composer require typo3/html-sanitizer:^1.5.32.0.0Fixed in: 2.1.4composer require typo3/html-sanitizer:^2.1.4References
- https://github.com/TYPO3/html-sanitizer/security/advisories/GHSA-mm79-jhqm-9j54[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2023-47125[ADVISORY]
- https://github.com/TYPO3/html-sanitizer/commit/b8f90717251d968c49dc77f8c1e5912e2fbe0dff[WEB]
- https://github.com/TYPO3/html-sanitizer[PACKAGE]
- https://typo3.org/security/advisory/typo3-core-sa-2023-007[WEB]