Lucene search

K
osvGoogleOSV:GHSA-WG8H-GXF4-G4GH
HistoryMay 30, 2024 - 2:48 p.m.

TYPO3 Cross-Site Scripting in Online Media Asset Rendering

2024-05-3014:48:31
Google
osv.dev
6
typo3
cross-site scripting
online media asset
rendering
vulnerability
user input
encoding
backend user
server system
sftp

AI Score

6.7

Confidence

High

Failing to properly encode user input, online media asset rendering (*.youtube and *.vimeo files) is vulnerable to cross-site scripting. A valid backend user account or write access on the server system (e.g. SFTP) is needed in order to exploit this vulnerability.

AI Score

6.7

Confidence

High