Lucene search

K
typo3TYPO3 AssociationTYPO3-CORE-SA-2021-007
HistoryMar 16, 2021 - 12:00 a.m.

Cross-Site Scripting in Content Preview

2021-03-1600:00:00
TYPO3 Association
typo3.org
34

0.001 Low

EPSS

Percentile

26.4%

It has been discovered that database fields used as descriptionColumn are vulnerable to cross-site scripting when their content gets previewed in the page module. A valid backend user account is needed to exploit this vulnerability.

0.001 Low

EPSS

Percentile

26.4%