Lucene search

K
osvGoogleOSV:GHSA-4J77-GG36-9864
HistoryMay 13, 2020 - 11:18 p.m.

Cross-Site Scripting in TYPO3 CMS Link Handling

2020-05-1323:18:12
Google
osv.dev
4

0.001 Low

EPSS

Percentile

21.4%

It has been discovered that link tags generated by typolink functionality are vulnerable to cross-site scripting - properties being assigned as HTML attributes have not been parsed correctly.

Update to TYPO3 versions 9.5.17 or 10.4.2 that fix the problem described.

References

0.001 Low

EPSS

Percentile

21.4%