VDB
Sign up
MEDIUM

GHSA-w3v6-r62r-fvqh

Typo3 API XSS Vulnerabilities

Quick fix

GHSA-w3v6-r62r-fvqh — typo3/cms: upgrade to the fixed version with the command below.

composer require typo3/cms:^4.4.14

Details

The `t3lib_div::RemoveXSS` API method in TYPO3 4.4.0 through 4.4.13, 4.5.0 through 4.5.13, 4.6.0 through 4.6.6, 4.7, and 6.0 allows remote attackers to bypass the cross-site scripting (XSS) protection mechanism and inject arbitrary web script or HTML via non printable characters.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/typo3/cms
Introduced in: 4.4.0Fixed in: 4.4.14
Fixcomposer require typo3/cms:^4.4.14
Packagist/typo3/cms
Introduced in: 4.5.0Fixed in: 4.5.14
Fixcomposer require typo3/cms:^4.5.14
Packagist/typo3/cms
Introduced in: 4.6.0Fixed in: 4.6.7
Fixcomposer require typo3/cms:^4.6.7

References