Lucene search

K
typo3TYPO3 AssociationTYPO3-CORE-SA-2020-012
HistoryNov 17, 2020 - 12:00 a.m.

XML External Entity in Dashboard Widget

2020-11-1700:00:00
TYPO3 Association
typo3.org
21
rss widgets
vulnerability
theoretical
php
software
system distributions

EPSS

0.001

Percentile

31.4%

It has been discovered that RSS widgets are susceptible to XML external entity processing.
This vulnerability is reasonable, but is theoretical - it was not possible to actually reproduce the vulnerability with current PHP versions of supported and maintained system distributions.

EPSS

0.001

Percentile

31.4%