GHSA-qj69-chjp-g4f5

Suggest an improvement
Source
https://github.com/advisories/GHSA-qj69-chjp-g4f5
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-qj69-chjp-g4f5/GHSA-qj69-chjp-g4f5.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-qj69-chjp-g4f5
Aliases
  • CVE-2013-7078
Published
2022-05-17T01:29:44Z
Modified
2023-11-08T03:57:27.705697Z
Summary
TYPO3 Cross-site scripting (XSS) vulnerability in the Extbase Framework
Details

Cross-site scripting (XSS) vulnerability in the errorAction method in the ActionController base class in the Extbase Framework in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, 6.0.0 through 6.0.11, and 6.1.0 through 6.1.6, when the Rewritten Property Mapper is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified input, which is returned in an error message. NOTE: this might be the same vulnerability as CVE-2013-7072.

Database specific
{
    "nvd_published_at": "2014-01-19T18:55:00Z",
    "github_reviewed_at": "2023-08-28T23:36:19Z",
    "cwe_ids": [
        "CWE-79"
    ],
    "github_reviewed": true,
    "severity": "LOW"
}
References

Affected packages

Packagist / typo3/cms-core

Package

Name
typo3/cms-core
Purl
pkg:composer/typo3/cms-core

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.5.0
Fixed
4.5.31

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-qj69-chjp-g4f5/GHSA-qj69-chjp-g4f5.json"

Packagist / typo3/cms-core

Package

Name
typo3/cms-core
Purl
pkg:composer/typo3/cms-core

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.7.0
Fixed
4.7.16

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-qj69-chjp-g4f5/GHSA-qj69-chjp-g4f5.json"

Packagist / typo3/cms-core

Package

Name
typo3/cms-core
Purl
pkg:composer/typo3/cms-core

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.1.0
Fixed
6.1.6

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-qj69-chjp-g4f5/GHSA-qj69-chjp-g4f5.json"

Packagist / typo3/cms-core

Package

Name
typo3/cms-core
Purl
pkg:composer/typo3/cms-core

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.0.0
Fixed
6.0.11

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-qj69-chjp-g4f5/GHSA-qj69-chjp-g4f5.json"