GHSA-43gj-mj2w-wh46

Suggest an improvement
Source
https://github.com/advisories/GHSA-43gj-mj2w-wh46
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/05/GHSA-43gj-mj2w-wh46/GHSA-43gj-mj2w-wh46.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-43gj-mj2w-wh46
Aliases
Published
2020-05-13T23:17:48Z
Modified
2026-07-08T06:00:31Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
Cross-Site Scripting in TYPO3 CMS Form Engine
Details

In TYPO3 CMS greater than or equal to 9.0.0 and less than 9.5.17 and greater than or equal to 10.0.0 and less than 10.4.2, it has been discovered that HTML placeholder attributes containing data of other database records are vulnerable to cross-site scripting. A valid backend user account is needed to exploit this vulnerability.

Update to TYPO3 versions 9.5.17 or 10.4.2 that fix the problem described.

References

Database specific
{
    "cwe_ids":  [
        "CWE-79"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2020-05-13T22:54:40Z",
    "nvd_published_at":  null,
    "severity":  "MODERATE"
}
References

Affected packages

Packagist / typo3/cms-core

Package

Name
typo3/cms-core
Purl
pkg:composer/typo3/cms-core

Affected ranges

Type
ECOSYSTEM
Events
Introduced
9.0.0
Fixed
9.5.17

Affected versions

v9.*
v9.0.0
v9.1.0
v9.2.0
v9.2.1
v9.3.0
v9.3.1
v9.3.2
v9.3.3
v9.4.0
v9.5.0
v9.5.1
v9.5.2
v9.5.3
v9.5.4
v9.5.5
v9.5.6
v9.5.7
v9.5.8
v9.5.9
v9.5.10
v9.5.11
v9.5.12
v9.5.13
v9.5.14
v9.5.15
v9.5.16

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/05/GHSA-43gj-mj2w-wh46/GHSA-43gj-mj2w-wh46.json"

Packagist / typo3/cms-core

Package

Name
typo3/cms-core
Purl
pkg:composer/typo3/cms-core

Affected ranges

Type
ECOSYSTEM
Events
Introduced
10.0.0
Fixed
10.4.2

Affected versions

v10.*
v10.0.0
v10.1.0
v10.2.0
v10.2.1
v10.2.2
v10.3.0
v10.4.0
v10.4.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/05/GHSA-43gj-mj2w-wh46/GHSA-43gj-mj2w-wh46.json"

Packagist / typo3/cms

Package

Name
typo3/cms
Purl
pkg:composer/typo3/cms

Affected ranges

Type
ECOSYSTEM
Events
Introduced
10.0.0
Fixed
10.4.2

Affected versions

v10.*
v10.0.0
v10.1.0
v10.2.0
v10.2.1
v10.2.2
v10.3.0
v10.4.0
v10.4.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/05/GHSA-43gj-mj2w-wh46/GHSA-43gj-mj2w-wh46.json"

Packagist / typo3/cms

Package

Name
typo3/cms
Purl
pkg:composer/typo3/cms

Affected ranges

Type
ECOSYSTEM
Events
Introduced
9.0.0
Fixed
9.5.17

Affected versions

v9.*
v9.0.0
v9.1.0
v9.2.0
v9.2.1
v9.3.0
v9.3.1
v9.3.2
v9.3.3
v9.4.0
v9.5.0
v9.5.1
v9.5.2
v9.5.3
v9.5.4
v9.5.5
v9.5.6
v9.5.7
v9.5.8
v9.5.9
v9.5.10
v9.5.11
v9.5.12
v9.5.13
v9.5.14
v9.5.15
v9.5.16

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/05/GHSA-43gj-mj2w-wh46/GHSA-43gj-mj2w-wh46.json"